CVE-2013-1221

CRITICAL

The Tomcat Web Management feature in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly configure Tomcat components, which allows remote attackers to execute ar...

Affects 1 product across 1 vendor.

CVSS 2.010.0
EPSS3.4%
Percentile89th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-16: CWE-16
◆ AI Analysis — automated analysis, not human-reviewed

This vulnerability was disclosed in 2013. A critical vulnerability affects Cisco systems (CVE-2013-1221). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2013-GLOBAL-093770-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2013-1221?
This vulnerability was disclosed in 2013. A critical vulnerability affects Cisco systems (CVE-2013-1221). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2013-1221?
CVE-2013-1221 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 3.4%.
Is CVE-2013-1221 actively exploited?
No confirmed active exploitation of CVE-2013-1221 as of 2026-09-25.
How do I remediate CVE-2013-1221?
Priority: MEDIUM. Advisory: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130508-cvp PSIRT: [email protected]
What systems are affected by CVE-2013-1221?
CVE-2013-1221 affects: Cisco.
Vulnerability Details
CVE IDCVE-2013-1221
BSIDBS-2013-GLOBAL-093770-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2013-05-09
Last Modified2026-06-16
ICS Relevance55%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

The Tomcat Web Management feature in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly configure Tomcat components, which allows remote attackers to execute arbitrary code via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCub38384.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: The Tomcat Web Management feature in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly configure Tomcat components, which allows remote attackers to execute arbitrary code via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCub38384. CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductAffected Versions
Cisco Unified Customer Voice Portal ≤ 9.0(1)
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: October 2026 | Threat Age: 4898 Days
CISA known-exploitedNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
AI Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash4bab23e645106be937b8019e640fd58faf0443de37656db90587e7be2ff3dc0119fbdff2c76f37ade1eb6f68ea312b009d177fb87a37241cea2cbb7fe46afb23
Related CVEs affecting Cisco
CVE-2011-0382 10.0 The CGI subsystem on Cisco TelePresence Recording Server devices with softwar... CVE-2011-2738 10.0 Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before ... CVE-2007-2036 10.0 The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 200... CVE-2007-4241 10.0 Buffer overflow in ldcconn in Hewlett-Packard (HP) Controller for Cisco Local... CVE-2009-0617 10.0 Cisco Application Networking Manager (ANM) before 2.0 uses a default MySQL ro...
View all Cisco CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →