CVE-2013-3395: CSRF
Cross-site request forgery (CSRF) vulnerability in the web framework on Cisco IronPort Web Security Appliance (WSA) devices, Email Security Appliance (ESA) devices, and Content Security Management Appliance (SMA) devices allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCuh70263, CSCuh70323, and CSCuh26634.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3395?
CVE-2013-3395 has a Common Vulnerability Scoring System (CVSS) score indicating a medium severity level due to its potential for cross-site request forgery attacks.
How do I fix CVE-2013-3395?
To fix CVE-2013-3395, ensure that you have installed the latest security patches from Cisco for affected devices.
Which devices are affected by CVE-2013-3395?
CVE-2013-3395 affects Cisco IronPort Web Security Appliance, Email Security Appliance, and Content Security Management Appliance devices.
What type of attack is CVE-2013-3395 associated with?
CVE-2013-3395 is associated with cross-site request forgery (CSRF) attacks that can hijack user authentication.
Can CVE-2013-3395 lead to unauthorized access?
Yes, if exploited, CVE-2013-3395 can allow remote attackers to gain unauthorized access by hijacking the authentication of legitimate users.