CVE-2013-6492 describes a security bypass vulnerability in the Piranha Configuration Tool, specifically affecting Piranha version 0.8.6. This flaw allows remote attackers to bypass authentication and gain unauthorized read or modify access to the LVS configuration through crafted HTTP POST requests. With a CVSS score of 5.8, this vulnerability is considered medium severity, indicating that an attacker on the adjacent network can exploit it with low complexity to achieve partial confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation or Metasploit modules, an exploit is publicly available on ExploitDB, though community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.8.6CPE matchmatch criteria | cpe:2.3:a:ryan_ohara:piranha:0.8.6:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:A/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.