Lucene search

K
ciscoCiscoCISCO-SA-20150707-CVE-2015-4240
HistoryJul 07, 2015 - 8:48 p.m.

Cisco IP Communicator Web Access Denial of Service Vulnerability

2015-07-0720:48:27
tools.cisco.com
22

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.001

Percentile

48.6%

A vulnerability in the web interface of Cisco IP Communicator could allow an unauthenticated, remote attacker to take the web service offline.

The vulnerability is due to access of a specific HTTP URL. An attacker could exploit this vulnerability by sending an HTTP GET request to the specific URL. A successful exploit could allow the attacker to take the web service offline, resulting in a denial of service (DoS) condition.

Cisco has confirmed the vulnerability and released software updates.

To exploit this vulnerability, an attacker may need to gather additional information about the targeted device, such as whether the device has web access enabled. Web access must be enabled for a successful exploit.

Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Affected configurations

Vulners
Node
ciscoip_communicatorMatchany
OR
ciscoip_communicatorMatchany
VendorProductVersionCPE
ciscoip_communicatoranycpe:2.3:a:cisco:ip_communicator:any:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.001

Percentile

48.6%

Related for CISCO-SA-20150707-CVE-2015-4240