Lucene search

K
cveCiscoCVE-2015-4209
HistoryJun 23, 2015 - 2:59 p.m.

CVE-2015-4209

2015-06-2314:59:04
CWE-200
cisco
web.nvd.nist.gov
30
cisco
webex
meeting center
authorization
vulnerability
cve-2015-4209
nvd

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:N/A:P

AI Score

6.4

Confidence

Low

EPSS

0.003

Percentile

68.4%

Cisco WebEx Meeting Center does not properly determine authorization for reading a host calendar, which allows remote attackers to obtain sensitive information by obtaining a list of all meetings and then sending a calendar request for each one, aka Bug ID CSCur23913.

Affected configurations

Nvd
Node
ciscowebex_meeting_centerMatch-
VendorProductVersionCPE
ciscowebex_meeting_center-cpe:2.3:a:cisco:webex_meeting_center:-:*:*:*:*:*:*:*

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:N/A:P

AI Score

6.4

Confidence

Low

EPSS

0.003

Percentile

68.4%

Related for CVE-2015-4209