The web interface in Cisco MediaSense does not properly protect the client-server communication channel, which allows remote attackers to obtain sensitive query string or cookie information via unspecified vectors, aka Bug ID CSCuj23344.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-5502 | vendor advisory |
http://tools.cisco.com/security/center/viewAlert.x?alertId=30934 | vendor advisory |
http://osvdb.org/97532 | vdb entry |