CVE-2013-3431

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
25/07/2013
Last modified:
11/04/2025

Description

Cisco Video Surveillance Manager (VSM) before 7.0.0 does not require authentication for access to VSMC monitoring pages, which allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv40169.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cisco:video_surveillance_manager:*:*:*:*:*:*:*:* 6.3.3 (including)
cpe:2.3:a:cisco:video_surveillance_manager:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:video_surveillance_manager:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:video_surveillance_manager:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:video_surveillance_manager:2.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:video_surveillance_manager:2.1.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:video_surveillance_manager:2.1.3:*:*:*:*:*:*:*
cpe:2.3:a:cisco:video_surveillance_manager:2.1.4:*:*:*:*:*:*:*
cpe:2.3:a:cisco:video_surveillance_manager:2.1.6:*:*:*:*:*:*:*
cpe:2.3:a:cisco:video_surveillance_manager:2.1.7:*:*:*:*:*:*:*
cpe:2.3:a:cisco:video_surveillance_manager:2.3.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:video_surveillance_manager:2.3.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:video_surveillance_manager:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:video_surveillance_manager:4.2.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:video_surveillance_manager:4.2.1:*:*:*:*:*:*:*