« Volver al listado

CVE-2013-2756

Estado: ModificadaMedia (5)—

Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C allows remote attackers to bypass the console proxy authentication by leveraging knowledge of the source code.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-2756",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-05-23T14:55:10.867",
  "references": [
    {
      "url": "http://mail-archives.apache.org/mod_mbox/cloudstack-dev/201304.mbox/%3C51786984.1060300%40stratosec.co%3E",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/92748",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/53175",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/53204",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://support.citrix.com/article/CTX135815",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/59463",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id/1028473",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/83781",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://mail-archives.apache.org/mod_mbox/cloudstack-dev/201304.mbox/%3C51786984.1060300%40stratosec.co%3E",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/92748",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/53175",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/53204",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://support.citrix.com/article/CTX135815",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/59463",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1028473",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/83781",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C allows remote attackers to bypass the console proxy authentication by leveraging knowledge of the source code."
    },
    {
      "lang": "es",
      "value": "Apache CloudStack 4.0.0 anterior a 4.0.2 y Citrix CloudPlatform (anteriormente Citrix CloudStack) 3.0.x anterior a 3.0.6 Patch C permite a atacantes remotos evadir la autenticación de proxy de consola mediante el conocimiento del código fuente."
    }
  ],
  "lastModified": "2026-06-16T23:53:55.337",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:cloudstack:4.0.0:incubating:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EA46B1B9-FCD7-4F3D-88E6-95B1A5A0497C"
            },
            {
              "criteria": "cpe:2.3:a:apache:cloudstack:4.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C96C7798-F716-44DA-A57F-3103E001236B"
            },
            {
              "criteria": "cpe:2.3:a:apache:cloudstack:4.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "737C672C-D820-41B9-88E3-97DC113D9290"
            },
            {
              "criteria": "cpe:2.3:a:citrix:cloudplatform:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F0DE26F1-B341-4A50-BF9A-42488250D319"
            },
            {
              "criteria": "cpe:2.3:a:citrix:cloudplatform:3.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "91ED0724-C941-49CC-B96F-207FA4425CF9"
            },
            {
              "criteria": "cpe:2.3:a:citrix:cloudplatform:3.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "969E1C34-D7A0-4B0C-B83C-146C73439EFA"
            },
            {
              "criteria": "cpe:2.3:a:citrix:cloudplatform:3.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1849E592-502C-43D3-834A-298DEFA9646C"
            },
            {
              "criteria": "cpe:2.3:a:citrix:cloudplatform:3.0.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "23469BDA-56CE-4F88-BC32-6F2AC8D60703"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}