First published: Wed Jan 08 2014(Updated: )
The administrative interface in Cisco Context Directory Agent (CDA) does not properly enforce authorization requirements, which allows remote authenticated users to obtain administrative access by hijacking a session, aka Bug ID CSCuj45347.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Context Directory Agent |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0651 has a medium severity rating due to the risk of unauthorized administrative access.
To fix CVE-2014-0651, ensure you apply the latest patches provided by Cisco for the Context Directory Agent software.
CVE-2014-0651 affects Cisco Context Directory Agent users who use the administrative interface.
CVE-2014-0651 is an authorization bypass vulnerability that allows session hijacking.
Yes, CVE-2014-0651 can be exploited remotely by authorized users to gain administrative access.