Lucene search

K
nvd[email protected]NVD:CVE-2015-4221
HistoryJun 26, 2015 - 10:59 a.m.

CVE-2015-4221

2015-06-2610:59:05
CWE-264
web.nvd.nist.gov
4

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

43.9%

Cisco Unified Communications Manager IM and Presence Service 9.1(1) does not properly restrict access to encrypted passwords, which allows remote attackers to determine cleartext passwords, and consequently execute arbitrary commands, by visiting an unspecified web page and then conducting a decryption attack, aka Bug ID CSCuq46194.

Affected configurations

Nvd
Node
ciscounified_communications_manager_im_and_presence_serviceMatch9.1\(1\)
VendorProductVersionCPE
ciscounified_communications_manager_im_and_presence_service9.1(1)cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:9.1\(1\):*:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

43.9%

Related for NVD:CVE-2015-4221