First published: Thu Dec 19 2013(Updated: )
Cross-site request forgery (CSRF) vulnerability in goform/Quick_setup on Cisco EPC3925 devices allows remote attackers to hijack the authentication of administrators for requests that change a password via the Password and PasswordReEnter parameters, aka Bug ID CSCuh37496.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco 3925 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6976 has a medium severity rating due to its potential impact on administrative authentication.
To fix CVE-2013-6976, you should update the firmware of your Cisco EPC3925 device to the latest version provided by Cisco.
CVE-2013-6976 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
CVE-2013-6976 affects users of the Cisco EPC3925 devices, particularly those with administrative access.
An attacker exploiting CVE-2013-6976 can hijack administrator authentication to change passwords on the affected device.