Lucene search

K
cveFlexeraCVE-2013-3935
HistoryJan 02, 2020 - 3:15 p.m.

CVE-2013-3935

2020-01-0215:15:11
CWE-352
flexera
web.nvd.nist.gov
67
opsview
csrf
vulnerability
administrator
password

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

29.2%

Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.1 and Opsview Core before 20130522 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via unspecified vectors.

Affected configurations

Nvd
Node
opsviewopsviewRange<4.4.1
OR
opsviewopsview_coreRange<20130522
VendorProductVersionCPE
opsviewopsview*cpe:2.3:a:opsview:opsview:*:*:*:*:*:*:*:*
opsviewopsview_core*cpe:2.3:a:opsview:opsview_core:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Opsview",
    "vendor": "Opsview",
    "versions": [
      {
        "status": "affected",
        "version": "before 4.4.1"
      }
    ]
  },
  {
    "product": "Opsview Core",
    "vendor": "Opsview",
    "versions": [
      {
        "status": "affected",
        "version": "before 20130522"
      }
    ]
  }
]

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

29.2%

Related for CVE-2013-3935