Lucene search

K
cveMitreCVE-2013-2756
HistoryMay 23, 2014 - 2:55 p.m.

CVE-2013-2756

2014-05-2314:55:10
CWE-287
mitre
web.nvd.nist.gov
27
cve-2013-2756
apache cloudstack
citrix cloudplatform
remote attack
authentication bypass

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

7.2

Confidence

Low

EPSS

0.002

Percentile

57.3%

Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C allows remote attackers to bypass the console proxy authentication by leveraging knowledge of the source code.

Affected configurations

Nvd
Node
apachecloudstackMatch4.0.0incubating
OR
apachecloudstackMatch4.0.1
OR
apachecloudstackMatch4.0.2
OR
citrixcloudplatformMatch3.0
OR
citrixcloudplatformMatch3.0.3
OR
citrixcloudplatformMatch3.0.4
OR
citrixcloudplatformMatch3.0.5
OR
citrixcloudplatformMatch3.0.6
VendorProductVersionCPE
apachecloudstack4.0.0cpe:2.3:a:apache:cloudstack:4.0.0:incubating:*:*:*:*:*:*
apachecloudstack4.0.1cpe:2.3:a:apache:cloudstack:4.0.1:*:*:*:*:*:*:*
apachecloudstack4.0.2cpe:2.3:a:apache:cloudstack:4.0.2:*:*:*:*:*:*:*
citrixcloudplatform3.0cpe:2.3:a:citrix:cloudplatform:3.0:*:*:*:*:*:*:*
citrixcloudplatform3.0.3cpe:2.3:a:citrix:cloudplatform:3.0.3:*:*:*:*:*:*:*
citrixcloudplatform3.0.4cpe:2.3:a:citrix:cloudplatform:3.0.4:*:*:*:*:*:*:*
citrixcloudplatform3.0.5cpe:2.3:a:citrix:cloudplatform:3.0.5:*:*:*:*:*:*:*
citrixcloudplatform3.0.6cpe:2.3:a:citrix:cloudplatform:3.0.6:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

7.2

Confidence

Low

EPSS

0.002

Percentile

57.3%

Related for CVE-2013-2756