ID

VAR-201307-0206


CVE

CVE-2013-3421


TITLE

Cisco Secure Access Control System Cross-site scripting vulnerability in the Help index page

Trust: 0.8

sources: JVNDB: JVNDB-2013-003343

DESCRIPTION

Cross-site scripting (XSS) vulnerability in the Help index page in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCud75170. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. This issue is being tracked by Cisco Bug ID CSCud75170. The system can respectively control network access and network device access through RADIUS and TACACS protocols

Trust: 1.98

sources: NVD: CVE-2013-3421 // JVNDB: JVNDB-2013-003343 // BID: 61171 // VULHUB: VHN-63423

AFFECTED PRODUCTS

vendor:ciscomodel:secure access control systemscope:eqversion: -

Trust: 1.6

vendor:ciscomodel:secure access control system softwarescope:eqversion:5.3

Trust: 0.8

vendor:ciscomodel:secure access control system softwarescope:eqversion:5.4

Trust: 0.8

vendor:ciscomodel:secure access control systemscope:eqversion:5.4.0.46.3

Trust: 0.3

vendor:ciscomodel:secure access control systemscope:eqversion:5.4.0.46.2

Trust: 0.3

vendor:ciscomodel:secure access control systemscope:eqversion:5.4.0.46.1

Trust: 0.3

vendor:ciscomodel:secure access control systemscope:eqversion:5.4

Trust: 0.3

vendor:ciscomodel:secure access control systemscope:eqversion:5.3.0.6

Trust: 0.3

vendor:ciscomodel:secure access control systemscope:eqversion:5.3.0.40.7

Trust: 0.3

vendor:ciscomodel:secure access control systemscope:eqversion:5.3.0.40.6

Trust: 0.3

vendor:ciscomodel:secure access control systemscope:eqversion:5.3.0.40.5

Trust: 0.3

vendor:ciscomodel:secure access control systemscope:eqversion:5.3.0.40.4

Trust: 0.3

vendor:ciscomodel:secure access control systemscope:eqversion:5.3.0.40.3

Trust: 0.3

vendor:ciscomodel:secure access control systemscope:eqversion:5.3.0.40.2

Trust: 0.3

vendor:ciscomodel:secure access control systemscope:eqversion:5.3.0.40.1

Trust: 0.3

vendor:ciscomodel:secure access control systemscope:eqversion:5.3.0.40

Trust: 0.3

sources: BID: 61171 // JVNDB: JVNDB-2013-003343 // CNNVD: CNNVD-201307-239 // NVD: CVE-2013-3421

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-3421
value: MEDIUM

Trust: 1.0

NVD: CVE-2013-3421
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201307-239
value: MEDIUM

Trust: 0.6

VULHUB: VHN-63423
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2013-3421
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-63423
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-63423 // JVNDB: JVNDB-2013-003343 // CNNVD: CNNVD-201307-239 // NVD: CVE-2013-3421

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-63423 // JVNDB: JVNDB-2013-003343 // NVD: CVE-2013-3421

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201307-239

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201307-239

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-003343

PATCH

title:Cisco Secure Access Control System Help Index Cross-Site Scripting Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-3421

Trust: 0.8

title:30066url:http://tools.cisco.com/security/center/viewAlert.x?alertId=30066

Trust: 0.8

sources: JVNDB: JVNDB-2013-003343

EXTERNAL IDS

db:NVDid:CVE-2013-3421

Trust: 2.8

db:JVNDBid:JVNDB-2013-003343

Trust: 0.8

db:CNNVDid:CNNVD-201307-239

Trust: 0.7

db:CISCOid:20130712 CISCO SECURE ACCESS CONTROL SYSTEM HELP INDEX CROSS-SITE SCRIPTING VULNERABILITY

Trust: 0.6

db:BIDid:61171

Trust: 0.4

db:VULHUBid:VHN-63423

Trust: 0.1

sources: VULHUB: VHN-63423 // BID: 61171 // JVNDB: JVNDB-2013-003343 // CNNVD: CNNVD-201307-239 // NVD: CVE-2013-3421

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2013-3421

Trust: 2.0

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/85622

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-3421

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-3421

Trust: 0.8

url:http://www.cisco.com/en/us/products/ps9911/index.html

Trust: 0.3

url:http://tools.cisco.com/security/center/viewalert.x?alertid=30066

Trust: 0.3

sources: VULHUB: VHN-63423 // BID: 61171 // JVNDB: JVNDB-2013-003343 // CNNVD: CNNVD-201307-239 // NVD: CVE-2013-3421

CREDITS

Cisco

Trust: 0.3

sources: BID: 61171

SOURCES

db:VULHUBid:VHN-63423
db:BIDid:61171
db:JVNDBid:JVNDB-2013-003343
db:CNNVDid:CNNVD-201307-239
db:NVDid:CVE-2013-3421

LAST UPDATE DATE

2025-04-11T23:18:54.370000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-63423date:2017-08-29T00:00:00
db:BIDid:61171date:2013-07-15T00:00:00
db:JVNDBid:JVNDB-2013-003343date:2013-07-16T00:00:00
db:CNNVDid:CNNVD-201307-239date:2013-07-18T00:00:00
db:NVDid:CVE-2013-3421date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:VULHUBid:VHN-63423date:2013-07-12T00:00:00
db:BIDid:61171date:2013-07-15T00:00:00
db:JVNDBid:JVNDB-2013-003343date:2013-07-16T00:00:00
db:CNNVDid:CNNVD-201307-239date:2013-07-18T00:00:00
db:NVDid:CVE-2013-3421date:2013-07-12T21:55:00.997