Lucene search

K
ciscoCiscoCISCO-SA-20130715-CVE-2013-3428
HistoryJul 15, 2013 - 4:15 p.m.

Cisco Secure Access Control System Error Condition Information Disclosure Vulnerability

2013-07-1516:15:32
tools.cisco.com
13

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

EPSS

0.001

Percentile

40.3%

An issue in the web interface of Cisco Secure Access Control System (ACS) could allow an authenticated, remote attacker to view detailed error message information.

The issue is due to insufficient filtering of error condition output. An attacker could exploit this issue by forcing the system to generate an error condition.

Cisco has confirmed this vulnerability in a security notice and released software updates.

To exploit this vulnerability, an attacker must authenticate to a targeted device. This access requirement decreases the likelihood of a successful exploit.

Affected configurations

Vulners
Node
ciscosecure_access_control_systemMatchany
OR
ciscosecure_access_control_systemMatchany
VendorProductVersionCPE
ciscosecure_access_control_systemanycpe:2.3:a:cisco:secure_access_control_system:any:*:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

EPSS

0.001

Percentile

40.3%

Related for CISCO-SA-20130715-CVE-2013-3428