Cloud Portal
Vendor:
First CVE: Feb 27, 2013 · Active for 13 years
9
Total CVEs
More Total CVEs than 86% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
4.4
Avg CVSS
Higher Avg CVSS than 4% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cloud Portal over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 27, 2013
13 years ago
Most Recent CVE
Aug 30, 2014
4,349 days ago
CVE Severity & Scoring
Cloud Portal9 CVEs
100%
All CVEs352,785 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown9 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown9 (100.0%)
User Interaction
None0 (0.0%)
Unknown9 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown9 (100.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-3352MEDIUM Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) 2008.3_SP9 and earlier does not properly consider whether a session is a problematic NULL session, which allows remo | Aug 30, 2014 | 4.3 | 16 | NO | NO |
CVE-2014-3351MEDIUM Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not properly consider whether a session is a problematic NULL session, which allows remote attackers to obtain | Aug 29, 2014 | 5.0 | 16 | NO | NO |
CVE-2013-6708MEDIUM Cisco Cloud Portal 9.4 allows remote attackers to read files of unspecified types via a direct request, aka Bug IDs CSCuj08426 and CSCui60889. | Dec 10, 2013 | 5.0 | 16 | NO | NO |
CVE-2014-0694MEDIUM Intelligent Automation for Cloud (IAC) in Cisco Cloud Portal 9.4.1 and earlier includes a cryptographic key in binary files, which makes it easier for remote attackers to obtain cl | Mar 14, 2014 | 5.0 | 15 | NO | NO |
CVE-2014-3350MEDIUM Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not properly implement URL redirection, which allows remote authenticated users to obtain sensitive information | Aug 29, 2014 | 4.0 | 14 | NO | NO |
CVE-2014-3349MEDIUM Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not validate file types during the handling of file submission, which allows remote authenticated users to uplo | Aug 29, 2014 | 4.0 | 14 | NO | NO |
CVE-2014-3298MEDIUM Form Data Viewer in Cisco Intelligent Automation for Cloud in Cisco Cloud Portal places passwords in form data, which allows remote authenticated users to obtain sensitive informat | Jul 2, 2014 | 4.0 | 14 | NO | NO |
CVE-2014-3297MEDIUM Cisco Intelligent Automation for Cloud in Cisco Cloud Portal does not properly restrict the content of MyServices action URLs, which allows remote authenticated users to obtain sen | Jul 2, 2014 | 4.0 | 14 | NO | NO |
CVE-2013-1139MEDIUM The nsAPI interface in Cisco Cloud Portal 9.1 SP1 and SP2, and 9.3 through 9.3.2, does not properly check privileges, which allows remote authenticated users to obtain sensitive in | Feb 27, 2013 | 4.0 | 13 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Cloud Portal
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.4 | 3 | 4.8 | 2.3% | 0 | 0 |
| 9.3.2 | 3 | 4.4 | 1.6% | 0 | 0 |
| 9.3.1 | 3 | 4.4 | 1.6% | 0 | 0 |
| 9.3 | 3 | 4.4 | 1.6% | 0 | 0 |
| 9.1 | 3 | 4.5 | 1.7% | 0 | 0 |
| 2008.3 | 1 | 4.3 | 2.8% | 0 | 0 |