CVE-2013-3428: Infoleak
Published Jul 15, 2013
·Updated
The web interface in Cisco Secure Access Control System (ACS) does not properly suppress error-condition details, which allows remote authenticated users to obtain sensitive information via an unspecified request that triggers an error, aka Bug ID CSCue65957.
Affected Software
1 affected component
Cisco Secure Access Control System
Event History
Jul 15, 2013
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3428?
CVE-2013-3428 is classified as a medium severity vulnerability.
2
How do I fix CVE-2013-3428?
To mitigate CVE-2013-3428, update Cisco Secure Access Control System to the latest version that addresses this vulnerability.
3
What type of information could be exposed due to CVE-2013-3428?
CVE-2013-3428 could allow remote authenticated users to access sensitive information related to system errors.
4
Who is affected by CVE-2013-3428?
CVE-2013-3428 affects users of the Cisco Secure Access Control System.
5
What is the nature of the vulnerability in CVE-2013-3428?
CVE-2013-3428 arises from the web interface failing to properly suppress error details, allowing sensitive data exposure.