Vulnslist

find the latest Cisco vulnerabilities

Cisco Server Provisioner Web Interface Information Disclosure Vulnerability

Cisco-SA-20131115-CVE-2013-3407 · Medium · Published · Updated

A vulnerability in the web interface of Cisco Server Provisioner could allow an unauthenticated, remote attacker to access some pages directly that should require authentication. The vulnerability is due to a failure to enforce access controls for the vulnerable pages. An attacker could exploit this vulnerability by directly browsing to the vulnerable pages. Cisco has confirmed the vulnerability in a security notice; however, software updates are not available. To exploit this vulnerability, it is likely that an attacker would need access to trusted, internal networks in which the targeted device may reside, which may decrease the likelihood of a successful exploit.

Workarounds

Administrators are advised to contact the vendor regarding future updates and releases.

Administrators are advised to allow only trusted users to have network access.

Administrators may consider using IP-based access control lists (ACLs) to allow only trusted systems to access the affected systems.

Administrators are advised to monitor affected systems.

CVEsCVE-2013-3407
Cisco Bug IDsCSCug65664
CVSS ScoreBase 5.0
Base 5.0 AV:N/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:U/RC:C
Product Names From Source
Cisco Server Provisioner Software

Related Products

Product CVE Evidence
Cisco Server Provisioner Software CVE-2013-3407 Cisco OpenVuln