PT-2015-1514 · Cisco · Cisco Unified Meetingplace Web Conferencing

Publicado

2015-07-24

·

Atualizado

2017-09-21

·

CVE-2015-4262

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Unified MeetingPlace Web Conferencing versions prior to 8.5(5) MR3 Cisco Unified MeetingPlace Web Conferencing versions prior to 8.6(2)
Description The issue is related to errors in handling registration data in the password change subsystem of Cisco Unified MeetingPlace Web Conferencing. It allows a remote attacker to reset arbitrary passwords due to the lack of additional checks for the session ID and the current password. This can be achieved via a crafted HTTP request.
Recommendations For versions prior to 8.5(5) MR3, update to version 8.5(5) MR3 or later. For versions prior to 8.6(2), update to version 8.6(2) or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-10801
CVE-2015-4262

Produtos afetados

Cisco Unified Meetingplace Web Conferencing