Lucene search

K
cveCiscoCVE-2016-6426
HistoryOct 05, 2016 - 9:59 p.m.

CVE-2016-6426

2016-10-0521:59:00
CWE-20
cisco
web.nvd.nist.gov
30
cisco
cuic
cve-2016-6426
security vulnerability
remote attack

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.003

Percentile

69.7%

The j_spring_security_switch_user function in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to create user accounts by visiting an unspecified web page, aka Bug IDs CSCuy75027 and CSCuy81653.

Affected configurations

Nvd
Node
ciscounified_contact_center_expressMatch10.0\(1\)
OR
ciscounified_contact_center_expressMatch10.5\(1\)
OR
ciscounified_contact_center_expressMatch10.6\(1\)
OR
ciscounified_contact_center_expressMatch11.0\(1\)
OR
ciscounified_intelligence_centerMatch8.5.4
OR
ciscounified_intelligence_centerMatch9.0\(2\)
OR
ciscounified_intelligence_centerMatch9.1\(1\)
VendorProductVersionCPE
ciscounified_contact_center_express10.0(1)cpe:2.3:a:cisco:unified_contact_center_express:10.0\(1\):*:*:*:*:*:*:*
ciscounified_contact_center_express10.5(1)cpe:2.3:a:cisco:unified_contact_center_express:10.5\(1\):*:*:*:*:*:*:*
ciscounified_contact_center_express10.6(1)cpe:2.3:a:cisco:unified_contact_center_express:10.6\(1\):*:*:*:*:*:*:*
ciscounified_contact_center_express11.0(1)cpe:2.3:a:cisco:unified_contact_center_express:11.0\(1\):*:*:*:*:*:*:*
ciscounified_intelligence_center8.5.4cpe:2.3:a:cisco:unified_intelligence_center:8.5.4:*:*:*:*:*:*:*
ciscounified_intelligence_center9.0(2)cpe:2.3:a:cisco:unified_intelligence_center:9.0\(2\):*:*:*:*:*:*:*
ciscounified_intelligence_center9.1(1)cpe:2.3:a:cisco:unified_intelligence_center:9.1\(1\):*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.003

Percentile

69.7%

Related for CVE-2016-6426