Lucene search

K
cveCiscoCVE-2013-1205
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2013-1205

2022-10-0316:14:47
CWE-287
cisco
web.nvd.nist.gov
24
cve-2013-1205
cisco webex
meetings server
security vulnerability
request authentication
remote attackers
host keys
event passwords

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

7.1

Confidence

Low

EPSS

0.002

Percentile

55.9%

The Event Center module in Cisco WebEx Meetings Server does not perform request authentication in all intended circumstances, which allows remote attackers to discover host keys and event passwords via crafted URLs, aka Bug ID CSCue62485.

Affected configurations

Nvd
Node
ciscowebex_meetings_serverMatch-
VendorProductVersionCPE
ciscowebex_meetings_server-cpe:/a:cisco:webex_meetings_server:-:::

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

7.1

Confidence

Low

EPSS

0.002

Percentile

55.9%

Related for CVE-2013-1205