PT-2010-1955 · Cisco · Cisco Unified Meetingplace

Published

2010-01-28

·

Updated

2010-01-31

·

CVE-2010-0140

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Unified MeetingPlace versions prior to 7.0(2.3) hotfix 5F Cisco Unified MeetingPlace version 6.0 before 6.0.639.3
Description The issue allows remote attackers to create user or administrator accounts via a crafted URL in a request to the internal interface.
Recommendations For Cisco Unified MeetingPlace version 6.0, update to version 6.0.639.3 or later. For Cisco Unified MeetingPlace version 7.0, apply hotfix 5F or later to version 7.0(2.3).

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2010-0140

Affected Products

Cisco Unified Meetingplace