First published: Mon Jul 15 2013(Updated: )
The web interface in Cisco Secure Access Control System (ACS) does not properly suppress error-condition details, which allows remote authenticated users to obtain sensitive information via an unspecified request that triggers an error, aka Bug ID CSCue65957.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Secure Access Control System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3428 is classified as a medium severity vulnerability.
To mitigate CVE-2013-3428, update Cisco Secure Access Control System to the latest version that addresses this vulnerability.
CVE-2013-3428 could allow remote authenticated users to access sensitive information related to system errors.
CVE-2013-3428 affects users of the Cisco Secure Access Control System.
CVE-2013-3428 arises from the web interface failing to properly suppress error details, allowing sensitive data exposure.