CVE-2013-1168
published 2013-04-11CVE-2013-1168: The web server in Cisco Unified MeetingPlace Application Server 7.x before 7.1MR1 Patch 2, 8.0 before 8.0MR1 Patch 1, and 8.5 before 8.5MR3 Patch 1 does not…
PriorityP335high7.6CVSS 2.0
AVNACHAuNCCICAC
EPSS
1.62%
73.4th percentile
The web server in Cisco Unified MeetingPlace Application Server 7.x before 7.1MR1 Patch 2, 8.0 before 8.0MR1 Patch 1, and 8.5 before 8.5MR3 Patch 1 does not invalidate a session upon a logout action, which makes it easier for remote attackers to hijack sessions by leveraging knowledge of a session cookie, aka Bug ID CSCuc64885.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace_solution | — | — |
CVSS provenance
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vendor_cisco9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fpmf-wc42-7p59: The web server in Cisco Unified MeetingPlace Application Server 7
ghsa_unreviewed·2022-05-17
CVE-2013-1168 [HIGH] GHSA-fpmf-wc42-7p59: The web server in Cisco Unified MeetingPlace Application Server 7
The web server in Cisco Unified MeetingPlace Application Server 7.x before 7.1MR1 Patch 2, 8.0 before 8.0MR1 Patch 1, and 8.5 before 8.5MR3 Patch 1 does not invalidate a session upon a logout action, which makes it easier for remote attackers to hijack sessions by leveraging knowledge of a session cookie, aka Bug ID CSCuc64885.
Cisco
Multiple Vulnerabilities in Cisco Unified MeetingPlace Solution
vendor_cisco·2013-04-10·CVSS 9.3
CVE-2013-1168 [CRITICAL] CWE-264 Multiple Vulnerabilities in Cisco Unified MeetingPlace Solution
Multiple Vulnerabilities in Cisco Unified MeetingPlace Solution
Cisco Unified MeetingPlace Application Server contains an authentication bypass vulnerability and Cisco Unified MeetingPlace Web Conferencing Server contains an arbitrary login vulnerability. For both vulnerabilities, successful exploitation could allow an unauthenticated, remote attacker to impersonate a legitimate user and send arbitrary commands to the affected system with the privileges of that user.
Cisco has released software updates that address these vulnerabilities. A workaround is available for the Cisco Unified MeetingPlace Web Conferencing Server Arbitrary Login Vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2
Cisco
Multiple Vulnerabilities in Cisco Unified MeetingPlace Solution
vendor_cisco
CVE-2013-1168 Multiple Vulnerabilities in Cisco Unified MeetingPlace Solution
CVE-2013-1168: Multiple Vulnerabilities in Cisco Unified MeetingPlace Solution
Cisco Unified MeetingPlace Application Server contains an authentication bypass vulnerability and Cisco Unified MeetingPlace Web Conferencing Server contains an arbitrary login vulnerability. For both vulnerabilities, successful exploitation could allow an unauthenticated, remote attacker to impersonate a legitimate user and send arbitrary commands to the affected system with the privileges of that user. Cisco has released software updates that address these vulnerabilities. A workaround is available for the Cisco Unified MeetingPlace Web Conferencing Server Arbitrary Login Vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-04-11
Published