ID

VAR-201305-0159


CVE

CVE-2013-1225


TITLE

Cisco Unified Customer Voice Portal XML Entity Expansion Remote Arbitrary File Access Vulnerability

Trust: 0.9

sources: BID: 59744 // CNNVD: CNNVD-201305-183

DESCRIPTION

Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to read arbitrary files via a Resource Manager (1) HTTP or (2) HTTPS request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCub38366. Cisco Unified Customer Voice Portal (CVP) Contains a vulnerability in which arbitrary files can be read. This case XML External entity (XXE) Vulnerability related to the problem. Remote attackers can exploit this issue to read arbitrary files. This may lead to further attacks. This issue is being tracked by Cisco Bug ID CSCub38366

Trust: 1.98

sources: NVD: CVE-2013-1225 // JVNDB: JVNDB-2013-002616 // BID: 59744 // VULHUB: VHN-61227

AFFECTED PRODUCTS

vendor:ciscomodel:unified customer voice portalscope:eqversion:4.1

Trust: 1.9

vendor:ciscomodel:unified customer voice portalscope:eqversion:4.0

Trust: 1.9

vendor:ciscomodel:unified customer voice portalscope:eqversion:3.0

Trust: 1.6

vendor:ciscomodel:unified customer voice portalscope:eqversion:8.0\(1\)

Trust: 1.6

vendor:ciscomodel:unified customer voice portalscope:eqversion:3.6\(10\)

Trust: 1.6

vendor:ciscomodel:unified customer voice portalscope:eqversion:7.0\(2\)

Trust: 1.6

vendor:ciscomodel:unified customer voice portalscope:eqversion:4.0\(2\)

Trust: 1.6

vendor:ciscomodel:unified customer voice portalscope:eqversion:7.0

Trust: 1.3

vendor:ciscomodel:unified customer voice portalscope:eqversion:9.0

Trust: 1.0

vendor:ciscomodel:unified customer voice portalscope:lteversion:9.0\(1\)

Trust: 1.0

vendor:ciscomodel:unified customer voice portalscope:eqversion:8.5\(1\)

Trust: 1.0

vendor:ciscomodel:unified customer voice portalscope:ltversion:9.0.1 es 11

Trust: 0.8

vendor:ciscomodel:unified customer voice portalscope:eqversion:9.0\(1\)

Trust: 0.6

vendor:ciscomodel:unified customer voice portalscope:eqversion:7.0(1)

Trust: 0.3

vendor:ciscomodel:unified customer voice portal 4.1 es11scope: - version: -

Trust: 0.3

vendor:ciscomodel:unified customer voice portal 4.0 es14scope: - version: -

Trust: 0.3

sources: BID: 59744 // JVNDB: JVNDB-2013-002616 // CNNVD: CNNVD-201305-183 // NVD: CVE-2013-1225

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-1225
value: HIGH

Trust: 1.0

NVD: CVE-2013-1225
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201305-183
value: HIGH

Trust: 0.6

VULHUB: VHN-61227
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2013-1225
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-61227
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-61227 // JVNDB: JVNDB-2013-002616 // CNNVD: CNNVD-201305-183 // NVD: CVE-2013-1225

PROBLEMTYPE DATA

problemtype:CWE-264

Trust: 1.9

sources: VULHUB: VHN-61227 // JVNDB: JVNDB-2013-002616 // NVD: CVE-2013-1225

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201305-183

TYPE

permissions and access control

Trust: 0.6

sources: CNNVD: CNNVD-201305-183

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-002616

PATCH

title:28982url:http://tools.cisco.com/security/center/viewAMBAlert.x?alertId=28982

Trust: 0.8

title:cisco-sa-20130508-cvpurl:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130508-cvp

Trust: 0.8

title:29159url:http://tools.cisco.com/security/center/viewAlert.x?alertId=29159

Trust: 0.8

title:cisco-sa-20130508-cvpurl:http://www.cisco.com/cisco/web/support/JP/111/1117/1117965_cisco-sa-20130508-cvp-j.html

Trust: 0.8

sources: JVNDB: JVNDB-2013-002616

EXTERNAL IDS

db:NVDid:CVE-2013-1225

Trust: 2.8

db:BIDid:59744

Trust: 1.0

db:JVNDBid:JVNDB-2013-002616

Trust: 0.8

db:CNNVDid:CNNVD-201305-183

Trust: 0.7

db:SECUNIAid:53306

Trust: 0.6

db:CISCOid:20130508 MULTIPLE VULNERABILITIES IN CISCO UNIFIED CUSTOMER VOICE PORTAL SOFTWARE

Trust: 0.6

db:VULHUBid:VHN-61227

Trust: 0.1

sources: VULHUB: VHN-61227 // BID: 59744 // JVNDB: JVNDB-2013-002616 // CNNVD: CNNVD-201305-183 // NVD: CVE-2013-1225

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20130508-cvp

Trust: 2.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-1225

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-1225

Trust: 0.8

url:http://secunia.com/advisories/53306

Trust: 0.6

url:http://www.securityfocus.com/bid/59744

Trust: 0.6

url:http://www.cisco.com/en/us/products/sw/custcosw/ps1006/index.html

Trust: 0.3

sources: VULHUB: VHN-61227 // BID: 59744 // JVNDB: JVNDB-2013-002616 // CNNVD: CNNVD-201305-183 // NVD: CVE-2013-1225

CREDITS

Alex Senkevitch

Trust: 0.9

sources: BID: 59744 // CNNVD: CNNVD-201305-183

SOURCES

db:VULHUBid:VHN-61227
db:BIDid:59744
db:JVNDBid:JVNDB-2013-002616
db:CNNVDid:CNNVD-201305-183
db:NVDid:CVE-2013-1225

LAST UPDATE DATE

2024-11-23T22:02:23.976000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-61227date:2013-05-09T00:00:00
db:BIDid:59744date:2013-05-08T00:00:00
db:JVNDBid:JVNDB-2013-002616date:2013-05-10T00:00:00
db:CNNVDid:CNNVD-201305-183date:2013-05-10T00:00:00
db:NVDid:CVE-2013-1225date:2024-11-21T01:49:08.987

SOURCES RELEASE DATE

db:VULHUBid:VHN-61227date:2013-05-09T00:00:00
db:BIDid:59744date:2013-05-08T00:00:00
db:JVNDBid:JVNDB-2013-002616date:2013-05-10T00:00:00
db:CNNVDid:CNNVD-201305-183date:2013-05-09T00:00:00
db:NVDid:CVE-2013-1225date:2013-05-09T12:31:19.243