CVE-2013-1223
published 2013-05-09CVE-2013-1223: The log viewer in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly validate an unspecified parameter, which allows…
PriorityP340high7.8CVSS 2.0
AVNACLAuNCCINAN
EPSS
1.48%
70.9th percentile
The log viewer in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly validate an unspecified parameter, which allows remote attackers to read arbitrary files via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCub38372.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_customer_voice_portal | <= 9.0\(1\) | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
| cisco | unified_customer_voice_portal | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software
vendor_cisco·2013-05-08·CVSS 10.0
CVE-2013-1220 [CRITICAL] CWE-119 Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software
Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software
Cisco Unified Customer Voice Portal Software (Unified CVP) contains multiple vulnerabilities. Various components of Cisco Unified CVP are affected; see the "Details" section for more information on the vulnerabilities. These vulnerabilities can be exploited independently; however, more than one vulnerability could be exploited on the same device.
Cisco has released software updates that address these vulnerabilities. Workarounds that mitigate some of these vulnerabilities are available.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130508-cvp
Cisco
Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software
vendor_cisco
CVE-2013-1223 Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software
CVE-2013-1223: Multiple Vulnerabilities in Cisco Unified Customer Voice Portal Software
Cisco Unified Customer Voice Portal Software (Unified CVP) contains multiple vulnerabilities. Various components of Cisco Unified CVP are affected; see the "
CWE: CWE-119, CWE-16, CWE-200, CWE-119, CWE-16, CWE-200, CWE-22, CWE-119, CWE-16, CWE-200, CWE-119, CWE-16, CWE-200, CWE-22
Bug IDs: CSCua65148, CSCub38366, CSCub38369, CSCua65148, CSCub38366
GHSA
GHSA-hvvh-mw8j-7rfj: The log viewer in Cisco Unified Customer Voice Portal (CVP) Software before 9
ghsa_unreviewed·2022-05-17
CVE-2013-1223 [HIGH] CWE-20 GHSA-hvvh-mw8j-7rfj: The log viewer in Cisco Unified Customer Voice Portal (CVP) Software before 9
The log viewer in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly validate an unspecified parameter, which allows remote attackers to read arbitrary files via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCub38372.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-05-09
Published