CVE-2013-3431
Summary
| CVE | CVE-2013-3431 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-07-25 15:53:16 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cisco Video Surveillance Manager (VSM) before 7.0.0 does not require authentication for access to VSMC monitoring pages, which allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv40169. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:C/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Video Surveillance Manager | 1.1.0 | All | All | All |
| Application | Cisco | Video Surveillance Manager | 1.2.1 | All | All | All |
| Application | Cisco | Video Surveillance Manager | 2.0.0 | All | All | All |
| Application | Cisco | Video Surveillance Manager | 2.1 | All | All | All |
| Application | Cisco | Video Surveillance Manager | 2.1.2 | All | All | All |
| Application | Cisco | Video Surveillance Manager | 2.1.3 | All | All | All |
| Application | Cisco | Video Surveillance Manager | 2.1.4 | All | All | All |
| Application | Cisco | Video Surveillance Manager | 2.1.6 | All | All | All |
| Application | Cisco | Video Surveillance Manager | 2.1.7 | All | All | All |
| Application | Cisco | Video Surveillance Manager | 2.3.0 | All | All | All |
| Application | Cisco | Video Surveillance Manager | 2.3.1 | All | All | All |
| Application | Cisco | Video Surveillance Manager | 4.0.1 | All | All | All |
| Application | Cisco | Video Surveillance Manager | 4.2.0 | All | All | All |
| Application | Cisco | Video Surveillance Manager | 4.2.1 | All | All | All |
| Application | Cisco | Video Surveillance Manager | 6.3 | All | All | All |
| Application | Cisco | Video Surveillance Manager | 6.3.1 | All | All | All |
| Application | Cisco | Video Surveillance Manager | 6.3.2 | All | All | All |
| Application | Cisco | Video Surveillance Manager | 6.3.2 | mr1 | All | All |
| Application | Cisco | Video Surveillance Manager | 6.3.2 | mr2 | All | All |
| Application | Cisco | Video Surveillance Manager | 6.3.2 | mr3 | All | All |
| Application | Cisco | Video Surveillance Manager | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Video Surveillance Manager CVE-2013-3431 Remote Authentication Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Cisco Security Advisory: Multiple Vulnerabilities in the Cisco Video Surveillance Manager | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Cisco Video Surveillance Manager Bugs Let Remote Users Obtain Potentially Sensitive Information - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.