Lucene search

K
cve[email protected]CVE-2013-1120
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2013-1120

2022-10-0316:14:48
CWE-352
web.nvd.nist.gov
25
cisco
unity express
csrf
cve-2013-1120
bug id cscue35910
nvd
security vulnerabilities
remote attack

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.2 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

36.1%

Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Unity Express with software before 8.0 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCue35910.

Affected configurations

NVD
Node
ciscounity_express_softwareRange7.4
OR
ciscounity_express_softwareMatch1.1.1
OR
ciscounity_express_softwareMatch1.1.2
OR
ciscounity_express_softwareMatch2.0
OR
ciscounity_express_softwareMatch2.1
OR
ciscounity_express_softwareMatch2.2
OR
ciscounity_express_softwareMatch2.3
OR
ciscounity_express_softwareMatch3.0
OR
ciscounity_express_softwareMatch3.1
OR
ciscounity_express_softwareMatch3.2
OR
ciscounity_express_softwareMatch7.0
OR
ciscounity_express_softwareMatch7.1
OR
ciscounity_express_softwareMatch7.2
OR
ciscounity_express_softwareMatch7.3
AND
ciscounity_express

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.2 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

36.1%