CVE-2013-1223
 
Severity Score
7.8
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The log viewer in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly validate an unspecified parameter, which allows remote attackers to read arbitrary files via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCub38372.
El lector de log en Cisco Unified Customer Voice Portal (CVP) Software antes de v9.0.1 ES v11 no valida correctamente un parámetro sin especificar, lo que permite a atacantes remotos leer ficheros arbitrarios a través de peticiones modificadas (1) HTTP ó (2) HTTPS, también conocido como Bug ID CSCub38372.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2013-01-11 CVE Reserved
- 2013-05-09 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130508-cvp | 2013-05-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Unified Customer Voice Portal Search vendor "Cisco" for product "Unified Customer Voice Portal" | <= 9.0\(1\) Search vendor "Cisco" for product "Unified Customer Voice Portal" and version " <= 9.0\(1\)" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Unified Customer Voice Portal Search vendor "Cisco" for product "Unified Customer Voice Portal" | 3.0 Search vendor "Cisco" for product "Unified Customer Voice Portal" and version "3.0" | sr1 |
Affected
| ||||||
Cisco Search vendor "Cisco" | Unified Customer Voice Portal Search vendor "Cisco" for product "Unified Customer Voice Portal" | 3.0 Search vendor "Cisco" for product "Unified Customer Voice Portal" and version "3.0" | sr2 |
Affected
| ||||||
Cisco Search vendor "Cisco" | Unified Customer Voice Portal Search vendor "Cisco" for product "Unified Customer Voice Portal" | 3.6\(10\) Search vendor "Cisco" for product "Unified Customer Voice Portal" and version "3.6\(10\)" | es01 |
Affected
| ||||||
Cisco Search vendor "Cisco" | Unified Customer Voice Portal Search vendor "Cisco" for product "Unified Customer Voice Portal" | 4.0 Search vendor "Cisco" for product "Unified Customer Voice Portal" and version "4.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Unified Customer Voice Portal Search vendor "Cisco" for product "Unified Customer Voice Portal" | 4.0\(2\) Search vendor "Cisco" for product "Unified Customer Voice Portal" and version "4.0\(2\)" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Unified Customer Voice Portal Search vendor "Cisco" for product "Unified Customer Voice Portal" | 4.0\(2\) Search vendor "Cisco" for product "Unified Customer Voice Portal" and version "4.0\(2\)" | sr1 |
Affected
| ||||||
Cisco Search vendor "Cisco" | Unified Customer Voice Portal Search vendor "Cisco" for product "Unified Customer Voice Portal" | 4.1 Search vendor "Cisco" for product "Unified Customer Voice Portal" and version "4.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Unified Customer Voice Portal Search vendor "Cisco" for product "Unified Customer Voice Portal" | 7.0 Search vendor "Cisco" for product "Unified Customer Voice Portal" and version "7.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Unified Customer Voice Portal Search vendor "Cisco" for product "Unified Customer Voice Portal" | 7.0\(2\) Search vendor "Cisco" for product "Unified Customer Voice Portal" and version "7.0\(2\)" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Unified Customer Voice Portal Search vendor "Cisco" for product "Unified Customer Voice Portal" | 8.0\(1\) Search vendor "Cisco" for product "Unified Customer Voice Portal" and version "8.0\(1\)" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Unified Customer Voice Portal Search vendor "Cisco" for product "Unified Customer Voice Portal" | 8.5\(1\) Search vendor "Cisco" for product "Unified Customer Voice Portal" and version "8.5\(1\)" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Unified Customer Voice Portal Search vendor "Cisco" for product "Unified Customer Voice Portal" | 9.0 Search vendor "Cisco" for product "Unified Customer Voice Portal" and version "9.0" | - |
Affected
|