CVE-2013-3473
Summary
| CVE | CVE-2013-3473 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-09-20 18:55:09 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance before 9.1.1 does not properly determine the existence of an authenticated session, which allows remote attackers to discover usernames and passwords via an HTTP request, aka Bug ID CSCud32600. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:C/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Prime Central For Hosted Collaboration Solution Assurance | 1.0 | All | All | All |
| Application | Cisco | Prime Central For Hosted Collaboration Solution Assurance | 1.0.1 | All | All | All |
| Application | Cisco | Prime Central For Hosted Collaboration Solution Assurance | 8.6 | All | All | All |
| Application | Cisco | Prime Central For Hosted Collaboration Solution Assurance | 9.0 | All | All | All |
| Application | Cisco | Prime Central For Hosted Collaboration Solution Assurance | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Security Advisory: Cisco Prime Central for Hosted Collaboration Solution Assurance Unauthenticated Username and Password Enumeration Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.