Cisco Secure Access Control System CVE-2013-3424 Cross Site Request Forgery Vulnerability
BID:61175
Info
Cisco Secure Access Control System CVE-2013-3424 Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 61175 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-3424 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 16 2013 12:00AM |
| Updated: | Jul 16 2013 12:00AM |
| Credit: | Cisco |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco Secure Access Control System CVE-2013-3424 Cross Site Request Forgery Vulnerability
Cisco Secure Access Control System is prone to a cross-site request-forgery vulnerability.
Attackers can exploit this issue to perform certain administrative actions and to gain unauthorized access to the affected application.
This issue is being tracked by Cisco bug ID CSCud75177.
Cisco Secure Access Control System is prone to a cross-site request-forgery vulnerability.
Attackers can exploit this issue to perform certain administrative actions and to gain unauthorized access to the affected application.
This issue is being tracked by Cisco bug ID CSCud75177.
Exploit / POC
Cisco Secure Access Control System CVE-2013-3424 Cross Site Request Forgery Vulnerability
To exploit the issue an attacker must entice a user into visiting a malicious site.
To exploit the issue an attacker must entice a user into visiting a malicious site.
Solution / Fix
Cisco Secure Access Control System CVE-2013-3424 Cross Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cisco Secure Access Control System CVE-2013-3424 Cross Site Request Forgery Vulnerability
References:
References: