Lucene search

K
cveCiscoCVE-2013-1225
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2013-1225

2022-10-0316:14:48
CWE-264
cisco
web.nvd.nist.gov
29
cisco
cvp
software
9.0.1
es 11
xml
xxe
vulnerability
cve-2013-1225

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

AI Score

6.9

Confidence

Low

EPSS

0.002

Percentile

55.9%

Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to read arbitrary files via a Resource Manager (1) HTTP or (2) HTTPS request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCub38366.

Affected configurations

Nvd
Node
ciscounified_customer_voice_portalRange9.0\(1\)
OR
ciscounified_customer_voice_portalMatch3.0sr1
OR
ciscounified_customer_voice_portalMatch3.0sr2
OR
ciscounified_customer_voice_portalMatch3.6\(10\)es01
OR
ciscounified_customer_voice_portalMatch4.0
OR
ciscounified_customer_voice_portalMatch4.0\(2\)
OR
ciscounified_customer_voice_portalMatch4.0\(2\)sr1
OR
ciscounified_customer_voice_portalMatch4.1
OR
ciscounified_customer_voice_portalMatch7.0
OR
ciscounified_customer_voice_portalMatch7.0\(2\)
OR
ciscounified_customer_voice_portalMatch8.0\(1\)
OR
ciscounified_customer_voice_portalMatch8.5\(1\)
OR
ciscounified_customer_voice_portalMatch9.0
VendorProductVersionCPE
ciscounified_customer_voice_portal4.0cpe:/a:cisco:unified_customer_voice_portal:4.0:::
ciscounified_customer_voice_portal7.0cpe:/a:cisco:unified_customer_voice_portal:7.0:::
ciscounified_customer_voice_portal4.0%282%29cpe:/a:cisco:unified_customer_voice_portal:4.0%282%29:sr1::
ciscounified_customer_voice_portal3.0cpe:/a:cisco:unified_customer_voice_portal:3.0:sr1::
ciscounified_customer_voice_portal8.0%281%29cpe:/a:cisco:unified_customer_voice_portal:8.0%281%29:::
ciscounified_customer_voice_portal9.0cpe:/a:cisco:unified_customer_voice_portal:9.0:::
ciscounified_customer_voice_portal3.6%2810%29cpe:/a:cisco:unified_customer_voice_portal:3.6%2810%29:es01::
ciscounified_customer_voice_portal3.0cpe:/a:cisco:unified_customer_voice_portal:3.0:sr2::
ciscounified_customer_voice_portal4.1cpe:/a:cisco:unified_customer_voice_portal:4.1:::
ciscounified_customer_voice_portal7.0%282%29cpe:/a:cisco:unified_customer_voice_portal:7.0%282%29:::
Rows per page:
1-10 of 131

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

AI Score

6.9

Confidence

Low

EPSS

0.002

Percentile

55.9%