Lucene search

K
ciscoCiscoCISCO-SA-20150714-CVE-2015-4271
HistoryJul 14, 2015 - 12:42 p.m.

Cisco TelePresence Integrator C Series Multiple Request Parameter Vulnerability

2015-07-1412:42:06
tools.cisco.com
8

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

EPSS

0.002

Percentile

55.3%

A vulnerability in Cisco TelePresence Integrator C Series could allow an unauthenticated, remote attacker to bypass authentication.

The vulnerability is due to insufficient validation of user-supplied values. An attacker could exploit this vulnerability by sending multiple request parameters to an affected device.

Cisco has confirmed the vulnerability and released software updates.

A successful exploit of this vulnerability could allow an attacker to bypass authentication and gain unauthorized access to the targeted device. If successful, the attacker could have the ability to conduct further attacks, which may impact the confidentiality, integrity, or availability of the device.

Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Affected configurations

Vulners
Node
ciscotelepresence_tc_softwareMatchany
OR
ciscotelepresence_tc_softwareMatchany
VendorProductVersionCPE
ciscotelepresence_tc_softwareanycpe:2.3:a:cisco:telepresence_tc_software:any:*:*:*:*:*:*:*

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

EPSS

0.002

Percentile

55.3%

Related for CISCO-SA-20150714-CVE-2015-4271