Lucene search

K
cveCiscoCVE-2013-1197
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2013-1197

2022-10-0316:14:47
CWE-20
cisco
web.nvd.nist.gov
25
cisco
cup
xml parser
remote authentication
denial of service
xml
xmpp
bug id
cscue13912
cve-2013-1197

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:N/I:N/A:C

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

50.4%

The XML parser in the server in Cisco Unified Presence (CUP) allows remote authenticated users to cause a denial of service (jabberd daemon crash) via crafted XML content in an XMPP message, aka Bug ID CSCue13912.

Affected configurations

Nvd
Node
ciscounified_presenceMatch-
VendorProductVersionCPE
ciscounified_presence-cpe:/a:cisco:unified_presence:-:::

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:N/I:N/A:C

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

50.4%

Related for CVE-2013-1197