imPC@ndo IT

Tracker / CVE-2013-3473

CVE-2013-3473

High 7.8

The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance before 9.1.1 does not properly determine the existence of an authenticated session, which allows remote attackers to discover usernames and passwords via an HTTP request, aka Bug ID CSCud32600.

Affected products and versions

cisco prime_central_for_hosted_collaboration_solution_assurance
cisco prime_central_for_hosted_collaboration_solution_assurance · … → 9.1

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References