First published: Tue Jul 02 2013(Updated: )
Cross-site request forgery (CSRF) vulnerability in the web framework on Cisco IronPort Web Security Appliance (WSA) devices, Email Security Appliance (ESA) devices, and Content Security Management Appliance (SMA) devices allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCuh70263, CSCuh70323, and CSCuh26634.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Content Security Management | ||
Cisco Web Security Appliance | ||
Cisco Email Security Appliance |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3395 has a Common Vulnerability Scoring System (CVSS) score indicating a medium severity level due to its potential for cross-site request forgery attacks.
To fix CVE-2013-3395, ensure that you have installed the latest security patches from Cisco for affected devices.
CVE-2013-3395 affects Cisco IronPort Web Security Appliance, Email Security Appliance, and Content Security Management Appliance devices.
CVE-2013-3395 is associated with cross-site request forgery (CSRF) attacks that can hijack user authentication.
Yes, if exploited, CVE-2013-3395 can allow remote attackers to gain unauthorized access by hijacking the authentication of legitimate users.