CVE-2013-3431

Cisco Video Surveillance Manager < 6.3.3 - Authentication Bypass

Title source: rule

Description

Cisco Video Surveillance Manager (VSM) before 7.0.0 does not require authentication for access to VSMC monitoring pages, which allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv40169.

Exploits (1)

exploitdb WORKING POC
by Bassem · textwebappsjsp
https://www.exploit-db.com/exploits/24786

Scores

EPSS 0.0410
EPSS Percentile 88.4%

Classification

CWE
CWE-287
Status draft

Affected Products (21)

cisco/video_surveillance_manager < 6.3.3
cisco/video_surveillance_manager
cisco/video_surveillance_manager
cisco/video_surveillance_manager
cisco/video_surveillance_manager
cisco/video_surveillance_manager
cisco/video_surveillance_manager
cisco/video_surveillance_manager
cisco/video_surveillance_manager
cisco/video_surveillance_manager
cisco/video_surveillance_manager
cisco/video_surveillance_manager
cisco/video_surveillance_manager
cisco/video_surveillance_manager
cisco/video_surveillance_manager
... and 6 more

Timeline

Published Jul 25, 2013
Tracked Since Feb 18, 2026