First published: Wed Sep 04 2013(Updated: )
Cisco Mobility Services Engine does not properly set up the Oracle SSL service, which allows remote attackers to obtain an unauthenticated session to the database-replication port, and consequently obtain sensitive information, via an SSL connection, aka Bug ID CSCue50794.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Mobility Services Engine 3310 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3469 is classified as a critical vulnerability due to the potential for remote attackers to access sensitive information.
To mitigate CVE-2013-3469, it is recommended to update the Cisco Mobility Services Engine to the latest version available.
CVE-2013-3469 allows remote attackers to gain unauthorized access to the database-replication port, potentially exposing sensitive data.
Yes, CVE-2013-3469 can be exploited remotely, making it particularly dangerous for systems exposed to the internet.
CVE-2013-3469 specifically affects the Cisco Mobility Services Engine software.