2024-04-04 08:46:00 +00:00

128 lines
3.7 KiB
JSON

{
"id": "CVE-2013-5524",
"sourceIdentifier": "ykramarz@cisco.com",
"published": "2013-10-10T10:55:06.617",
"lastModified": "2017-08-29T01:33:49.373",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in the troubleshooting page in Cisco Identity Services Engine (ISE) 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCug77655."
},
{
"lang": "es",
"value": "Vulnerabilidad de inyecci\u00f3n XSS en la p\u00e1gina de soluci\u00f3n de problemas en Cisco Identity Services Engine (ISE) 1.2 y anteriores permite a atacantes remotos inyectar script web o HTML arbitrario a trav\u00e9s de par\u00e1metros sin especificar, tambi\u00e9n conocido como Bug ID CSCug77655."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 4.3
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cisco:identity_services_engine_software:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.2",
"matchCriteriaId": "63BC1BB0-33FB-4CBC-99AD-E9E6593B2A11"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cisco:identity_services_engine_software:1.0:*:*:*:*:*:*:*",
"matchCriteriaId": "CA49BB84-9E6B-4510-B2DF-178C2E6C0CBE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:cisco:identity_services_engine_software:1.1:*:*:*:*:*:*:*",
"matchCriteriaId": "50CE032F-3BD1-462D-B2DD-4088EA7CE037"
}
]
}
]
}
],
"references": [
{
"url": "http://osvdb.org/98166",
"source": "ykramarz@cisco.com"
},
{
"url": "http://secunia.com/advisories/55067",
"source": "ykramarz@cisco.com"
},
{
"url": "http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-5524",
"source": "ykramarz@cisco.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://tools.cisco.com/security/center/viewAlert.x?alertId=31159",
"source": "ykramarz@cisco.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://www.securityfocus.com/bid/62870",
"source": "ykramarz@cisco.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "http://www.securitytracker.com/id/1029155",
"source": "ykramarz@cisco.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/87722",
"source": "ykramarz@cisco.com"
}
]
}