Lucene search

K
cveCiscoCVE-2013-5497
HistorySep 19, 2013 - 6:55 p.m.

CVE-2013-5497

2013-09-1918:55:05
CWE-287
cisco
web.nvd.nist.gov
25
cisco
ips
cve-2013-5497
authentication
denial of service
bug
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

6.9

Confidence

High

EPSS

0.009

Percentile

82.7%

The authentication manager process in the web framework in Cisco Intrusion Prevention System (IPS) does not properly handle user tokens, which allows remote attackers to cause a denial of service (intermittent MainApp hang) via a crafted management-interface connection request, aka Bug ID CSCuf20148.

Affected configurations

Nvd
Node
ciscointrusion_prevention_system
VendorProductVersionCPE
ciscointrusion_prevention_system*cpe:2.3:h:cisco:intrusion_prevention_system:*:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

6.9

Confidence

High

EPSS

0.009

Percentile

82.7%

Related for CVE-2013-5497