Lucene search

K
nvd[email protected]NVD:CVE-2013-3409
HistoryOct 10, 2013 - 10:55 a.m.

CVE-2013-3409

2013-10-1010:55:06
CWE-255
web.nvd.nist.gov
2

CVSS2

4.3

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:S/C:P/I:P/A:P

AI Score

5.8

Confidence

Low

EPSS

0

Percentile

5.1%

The portal in Cisco Prime Central for Hosted Collaboration Solution (HCS) places cleartext credentials in temporary files, which allows local users to obtain sensitive information by leveraging weak file permissions to read these files, aka Bug IDs CSCuh33735 and CSCuh34230.

Affected configurations

Nvd
Node
ciscoprime_central_for_hosted_collaboration_solutionMatch-
VendorProductVersionCPE
ciscoprime_central_for_hosted_collaboration_solution-cpe:2.3:a:cisco:prime_central_for_hosted_collaboration_solution:-:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:S/C:P/I:P/A:P

AI Score

5.8

Confidence

Low

EPSS

0

Percentile

5.1%

Related for NVD:CVE-2013-3409