CVE-2013-1169
 
Severity Score
9.3
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Cisco Unified MeetingPlace Web Conferencing Server 7.x before 7.1MR1 Patch 2, 8.0 before 8.0MR1 Patch 2, and 8.5 before 8.5MR3 Patch 1, when the Remember Me option is used, does not properly verify cookies, which allows remote attackers to impersonate users via a crafted login request, aka Bug ID CSCuc64846.
Cisco Unified MeetingPlace Web Conferencing Server v7.x antes de v7.1MR1 revisión 2, v8.0 antes de v8.0MR1 revisión 2, y v8.5 antes de v8.5MR3 Patch 1, cuando la opción Remember Me se utiliza, no verificar correctamente las cookies, lo que permite a atacantes remotos suplantar usuarios a través de una solicitud de acceso hecha a mano, también conocido como Bug ID CSCuc64846.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2013-01-11 CVE Reserved
- 2013-04-11 CVE Published
- 2024-09-17 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130410-mp | 2013-04-15 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Unified Meetingplace Web Conferencing Server Search vendor "Cisco" for product "Unified Meetingplace Web Conferencing Server" | 7.1 Search vendor "Cisco" for product "Unified Meetingplace Web Conferencing Server" and version "7.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Unified Meetingplace Web Conferencing Server Search vendor "Cisco" for product "Unified Meetingplace Web Conferencing Server" | 8.0 Search vendor "Cisco" for product "Unified Meetingplace Web Conferencing Server" and version "8.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Unified Meetingplace Web Conferencing Server Search vendor "Cisco" for product "Unified Meetingplace Web Conferencing Server" | 8.5 Search vendor "Cisco" for product "Unified Meetingplace Web Conferencing Server" and version "8.5" | - |
Affected
|