Lucene search

K
cveCiscoCVE-2015-0704
HistoryApr 22, 2015 - 1:59 a.m.

CVE-2015-0704

2015-04-2201:59:00
CWE-352
cisco
web.nvd.nist.gov
28
cve-2015-0704
csrf
cisco unified meetingplace
remote attackers
user authentication

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

Low

EPSS

0.001

Percentile

32.7%

Multiple cross-site request forgery (CSRF) vulnerabilities in API features in Cisco Unified MeetingPlace 8.6(1.9) allow remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCus95884.

Affected configurations

Nvd
Node
ciscounified_meetingplaceMatch8.6\(1.9\)
VendorProductVersionCPE
ciscounified_meetingplace8.6(1.9)cpe:2.3:a:cisco:unified_meetingplace:8.6\(1.9\):*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

Low

EPSS

0.001

Percentile

32.7%

Related for CVE-2015-0704