Lucene search

K
cve[email protected]CVE-2014-3267
HistoryMay 26, 2014 - 12:25 a.m.

CVE-2014-3267

2014-05-2600:25:31
CWE-352
web.nvd.nist.gov
18
2
cisco
security manager
csrf
vulnerability
cve-2014-3267
nvd
bug id cscuo46427

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.5 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

50.7%

Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Security Manager 4.6 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that make unspecified changes, aka Bug ID CSCuo46427.

Affected configurations

NVD
Node
ciscosecurity_managerRange4.6
OR
ciscosecurity_managerMatch4.0-
OR
ciscosecurity_managerMatch4.0sp1
OR
ciscosecurity_managerMatch4.0.1-
OR
ciscosecurity_managerMatch4.0.1sp1
OR
ciscosecurity_managerMatch4.0.1sp2
OR
ciscosecurity_managerMatch4.1
OR
ciscosecurity_managerMatch4.1sp1
OR
ciscosecurity_managerMatch4.1sp2
OR
ciscosecurity_managerMatch4.2-
OR
ciscosecurity_managerMatch4.2sp1
OR
ciscosecurity_managerMatch4.3-
OR
ciscosecurity_managerMatch4.3sp1
OR
ciscosecurity_managerMatch4.3sp2
OR
ciscosecurity_managerMatch4.4-
OR
ciscosecurity_managerMatch4.4sp1
OR
ciscosecurity_managerMatch4.4sp2
OR
ciscosecurity_managerMatch4.5

Social References

More

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.5 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

50.7%

Related for CVE-2014-3267