Cisco Intelligent Automation for Cloud URL Redirection Vulnerability

Cisco-SA-20140829-CVE-2014-3350 · Medium · Published · Updated

Data: Cisco advisories · Cisco CSAF · NVD CVEs · NVD CPEs · CISA KEV · EPSS

A vulnerability in the URL redirection of Cisco Intelligent Automation for Cloud could allow an authenticated, remote attacker to obtain sensitive information. The vulnerability is due to improper sanitization of redirect URLs. An attacker could exploit this vulnerability by submitting crafted URLs. Cisco has confirmed the vulnerability in a security notice; however, software updates are not available. After a successful exploit, the attacker could redirect a targeted user to a malicious site in an attempt to obtain sensitive information.

Workarounds

Administrators are advised to contact the vendor regarding future updates and releases.

Administrators are advised to allow only privileged users to access administration or management systems.

Administrators are advised to allow only trusted users to have network access.

Users should verify that unsolicited links are safe to follow.

Administrators are advised to monitor affected systems.

CVEsCVE-2014-3350
Cisco Bug IDsCSCuh84870
CVSS ScoreBase 4.0
Base 4.0 AV:N/AC:L/Au:S/C:N/I:P/A:N/E:H/RL:U/RC:C

Products with public affected evidence