Lucene search

K
cveCiscoCVE-2013-3409
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2013-3409

2022-10-0316:14:45
CWE-255
cisco
web.nvd.nist.gov
23
cve
2013
3409
cisco
prime central
hcs
cleartext credentials
vulnerability
bug ids
cscuh33735
cscuh34230
nvd

CVSS2

4.3

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:S/C:P/I:P/A:P

AI Score

5.9

Confidence

Low

EPSS

0

Percentile

5.1%

The portal in Cisco Prime Central for Hosted Collaboration Solution (HCS) places cleartext credentials in temporary files, which allows local users to obtain sensitive information by leveraging weak file permissions to read these files, aka Bug IDs CSCuh33735 and CSCuh34230.

Affected configurations

Nvd
Node
ciscoprime_central_for_hosted_collaboration_solutionMatch-
VendorProductVersionCPE
ciscoprime_central_for_hosted_collaboration_solution-cpe:/a:cisco:prime_central_for_hosted_collaboration_solution:-:::

CVSS2

4.3

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:S/C:P/I:P/A:P

AI Score

5.9

Confidence

Low

EPSS

0

Percentile

5.1%

Related for CVE-2013-3409