Lucene search

K
cveCiscoCVE-2014-7996
HistoryNov 18, 2014 - 11:59 p.m.

CVE-2014-7996

2014-11-1823:59:04
CWE-352
cisco
web.nvd.nist.gov
24
cisco
cve-2014-7996
csrf
vulnerability
web framework
cisco integrated management controller
unified computing system
bug id cscuq45477

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

Low

EPSS

0.002

Percentile

58.4%

Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Integrated Management Controller in Cisco Unified Computing System allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuq45477.

Affected configurations

Nvd
Node
ciscounified_computing_systemMatch-
VendorProductVersionCPE
ciscounified_computing_system-cpe:2.3:h:cisco:unified_computing_system:-:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

Low

EPSS

0.002

Percentile

58.4%

Related for CVE-2014-7996