Lucene search

K
cveCiscoCVE-2015-4221
HistoryJun 26, 2015 - 10:59 a.m.

CVE-2015-4221

2015-06-2610:59:05
CWE-264
cisco
web.nvd.nist.gov
34
cisco
unified communications
vulnerability
security
cve-2015-4221
nvd

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

7.6

Confidence

Low

EPSS

0.001

Percentile

43.9%

Cisco Unified Communications Manager IM and Presence Service 9.1(1) does not properly restrict access to encrypted passwords, which allows remote attackers to determine cleartext passwords, and consequently execute arbitrary commands, by visiting an unspecified web page and then conducting a decryption attack, aka Bug ID CSCuq46194.

Affected configurations

Nvd
Node
ciscounified_communications_manager_im_and_presence_serviceMatch9.1\(1\)
VendorProductVersionCPE
ciscounified_communications_manager_im_and_presence_service9.1(1)cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:9.1\(1\):*:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

7.6

Confidence

Low

EPSS

0.001

Percentile

43.9%

Related for CVE-2015-4221