Lucene search

K
cveCiscoCVE-2009-0614
HistoryFeb 26, 2009 - 4:17 p.m.

CVE-2009-0614

2009-02-2616:17:20
CWE-287
cisco
web.nvd.nist.gov
25
cve-2009-0614
cisco
unified meetingplace
web conferencing
authentication bypass
remote code execution

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:P/I:P/A:C

AI Score

6.9

Confidence

Low

EPSS

0.004

Percentile

73.3%

Unspecified vulnerability in the Web Server in Cisco Unified MeetingPlace Web Conferencing 6.0 before 6.0(517.0) (aka 6.0 MR4) and 7.0 before 7.0(2) (aka 7.0 MR1) allows remote attackers to bypass authentication and obtain administrative access via a crafted URL.

Affected configurations

Nvd
Node
ciscounified_meetingplace_web_conferencingRange6.0\(171\)โ€“6.0\(517.0\)
OR
ciscounified_meetingplace_web_conferencingRange7.0\(1\)โ€“7.0\(2\)
VendorProductVersionCPE
ciscounified_meetingplace_web_conferencing*cpe:2.3:a:cisco:unified_meetingplace_web_conferencing:*:*:*:*:*:*:*:*

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:P/I:P/A:C

AI Score

6.9

Confidence

Low

EPSS

0.004

Percentile

73.3%