Lucene search

K
ciscoCiscoCISCO-SA-20140122-CVE-2014-0672
HistoryJan 22, 2014 - 6:53 p.m.

Cisco MediaSense Search and Play Authorization Vulnerability

2014-01-2218:53:51
tools.cisco.com
11

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

EPSS

0.002

Percentile

65.0%

A vulnerability in the Search and Play interface of Cisco MediaSense could allow an authenticated, remote attacker to access recordings in the Search and Play interface.

The vulnerability is due to insufficient authorization controls. An attacker could exploit this vulnerability by accessing the Search and Play interface. An exploit could allow the attacker to access recordings in the Search and Play interface.

Cisco has confirmed the vulnerability in a security notice; however, software updates are not available.

To exploit this vulnerability, an attacker must authenticate to a targeted system. This access requirement reduces the likelihood of a successful exploit.

Affected configurations

Vulners
Node
ciscomediasenseMatchany
OR
ciscomediasenseMatchany
VendorProductVersionCPE
ciscomediasenseanycpe:2.3:a:cisco:mediasense:any:*:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

EPSS

0.002

Percentile

65.0%

Related for CISCO-SA-20140122-CVE-2014-0672