ID

VAR-201307-0208


CVE

CVE-2013-3423


TITLE

Cisco Secure Access Control System of Web Interface cross-site scripting vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2013-003345

DESCRIPTION

Cross-site scripting (XSS) vulnerability in the web interface in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified field, aka Bug ID CSCud75174. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. This issue is being tracked by Cisco Bug ID CSCud75174. The system can respectively control network access and network device access through RADIUS and TACACS protocols

Trust: 1.98

sources: NVD: CVE-2013-3423 // JVNDB: JVNDB-2013-003345 // BID: 61173 // VULHUB: VHN-63425

AFFECTED PRODUCTS

vendor:ciscomodel:secure access control systemscope:eqversion: -

Trust: 1.6

vendor:ciscomodel:secure access control system softwarescope:lteversion:5.4.0.46.3

Trust: 0.8

vendor:ciscomodel:secure access control systemscope:eqversion:5.4.0.46.3

Trust: 0.3

vendor:ciscomodel:secure access control systemscope:eqversion:5.4.0.46.2

Trust: 0.3

vendor:ciscomodel:secure access control systemscope:eqversion:5.4.0.46.1

Trust: 0.3

vendor:ciscomodel:secure access control systemscope:eqversion:5.4

Trust: 0.3

vendor:ciscomodel:secure access control systemscope:eqversion:5.3.0.6

Trust: 0.3

vendor:ciscomodel:secure access control systemscope:eqversion:5.3.0.40.7

Trust: 0.3

vendor:ciscomodel:secure access control systemscope:eqversion:5.3.0.40.6

Trust: 0.3

vendor:ciscomodel:secure access control systemscope:eqversion:5.3.0.40.5

Trust: 0.3

vendor:ciscomodel:secure access control systemscope:eqversion:5.3.0.40.4

Trust: 0.3

vendor:ciscomodel:secure access control systemscope:eqversion:5.3.0.40.3

Trust: 0.3

vendor:ciscomodel:secure access control systemscope:eqversion:5.3.0.40.2

Trust: 0.3

vendor:ciscomodel:secure access control systemscope:eqversion:5.3.0.40.1

Trust: 0.3

vendor:ciscomodel:secure access control systemscope:eqversion:5.3.0.40

Trust: 0.3

vendor:ciscomodel:secure access control systemscope:eqversion:5.3

Trust: 0.3

sources: BID: 61173 // JVNDB: JVNDB-2013-003345 // CNNVD: CNNVD-201307-241 // NVD: CVE-2013-3423

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-3423
value: MEDIUM

Trust: 1.0

NVD: CVE-2013-3423
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201307-241
value: MEDIUM

Trust: 0.6

VULHUB: VHN-63425
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2013-3423
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-63425
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-63425 // JVNDB: JVNDB-2013-003345 // CNNVD: CNNVD-201307-241 // NVD: CVE-2013-3423

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-63425 // JVNDB: JVNDB-2013-003345 // NVD: CVE-2013-3423

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201307-241

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201307-241

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-003345

PATCH

title:Cisco Secure Access Control System Cross-Site Scripting Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3423

Trust: 0.8

title:30076url:http://tools.cisco.com/security/center/viewAlert.x?alertId=30076

Trust: 0.8

sources: JVNDB: JVNDB-2013-003345

EXTERNAL IDS

db:NVDid:CVE-2013-3423

Trust: 2.8

db:JVNDBid:JVNDB-2013-003345

Trust: 0.8

db:CNNVDid:CNNVD-201307-241

Trust: 0.7

db:CISCOid:20130712 CISCO SECURE ACCESS CONTROL SYSTEM CROSS-SITE SCRIPTING VULNERABILITY

Trust: 0.6

db:BIDid:61173

Trust: 0.4

db:VULHUBid:VHN-63425

Trust: 0.1

sources: VULHUB: VHN-63425 // BID: 61173 // JVNDB: JVNDB-2013-003345 // CNNVD: CNNVD-201307-241 // NVD: CVE-2013-3423

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2013-3423

Trust: 2.0

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/85624

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-3423

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-3423

Trust: 0.8

url:http://www.cisco.com/en/us/products/ps9911/index.html

Trust: 0.3

url:http://tools.cisco.com/security/center/viewalert.x?alertid=30066

Trust: 0.3

sources: VULHUB: VHN-63425 // BID: 61173 // JVNDB: JVNDB-2013-003345 // CNNVD: CNNVD-201307-241 // NVD: CVE-2013-3423

CREDITS

Cisco

Trust: 0.3

sources: BID: 61173

SOURCES

db:VULHUBid:VHN-63425
db:BIDid:61173
db:JVNDBid:JVNDB-2013-003345
db:CNNVDid:CNNVD-201307-241
db:NVDid:CVE-2013-3423

LAST UPDATE DATE

2024-08-14T14:52:37.787000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-63425date:2017-08-29T00:00:00
db:BIDid:61173date:2013-07-15T00:00:00
db:JVNDBid:JVNDB-2013-003345date:2013-07-16T00:00:00
db:CNNVDid:CNNVD-201307-241date:2013-07-18T00:00:00
db:NVDid:CVE-2013-3423date:2017-08-29T01:33:23.073

SOURCES RELEASE DATE

db:VULHUBid:VHN-63425date:2013-07-12T00:00:00
db:BIDid:61173date:2013-07-15T00:00:00
db:JVNDBid:JVNDB-2013-003345date:2013-07-16T00:00:00
db:CNNVDid:CNNVD-201307-241date:2013-07-18T00:00:00
db:NVDid:CVE-2013-3423date:2013-07-12T21:55:01.040