Cisco Personal Assistant Web Interface User Password Bypass Vulnerability
BID:9384
Info
Cisco Personal Assistant Web Interface User Password Bypass Vulnerability
| Bugtraq ID: | 9384 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 08 2004 12:00AM |
| Updated: | Jan 08 2004 12:00AM |
| Credit: | This issue was announced by Cisco. |
| Vulnerable: |
Cisco Personal Assistant 1.4 (2) Cisco Personal Assistant 1.4 (1) |
| Not Vulnerable: |
Cisco Personal Assistant 1.3 (4) Cisco Personal Assistant 1.3 (3) Cisco Personal Assistant 1.3 (2) Cisco Personal Assistant 1.3 (1) |
Discussion
Cisco Personal Assistant Web Interface User Password Bypass Vulnerability
A vulnerability was reported in Cisco Personal Assistant that may permit remote attackers to bypass authentication via the web interface, allowing for unauthorized access to individual user configuration facilities.
It should be noted that Cisco Personal Assistant versions 1.3(x) and earlier are not affected.
A vulnerability was reported in Cisco Personal Assistant that may permit remote attackers to bypass authentication via the web interface, allowing for unauthorized access to individual user configuration facilities.
It should be noted that Cisco Personal Assistant versions 1.3(x) and earlier are not affected.
Exploit / POC
Cisco Personal Assistant Web Interface User Password Bypass Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Cisco Personal Assistant Web Interface User Password Bypass Vulnerability
Solution:
The vendor has stated the this issue can be addressed by applying available workarounds and does not require a software upgrade.
Solution:
The vendor has stated the this issue can be addressed by applying available workarounds and does not require a software upgrade.
References
Cisco Personal Assistant Web Interface User Password Bypass Vulnerability
References:
References: