PT-2010-1955 · Cisco · Cisco Unified Meetingplace
Published
2010-01-28
·
Updated
2010-01-31
·
CVE-2010-0140
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Unified MeetingPlace versions prior to 7.0(2.3) hotfix 5F
Cisco Unified MeetingPlace version 6.0 before 6.0.639.3
Description
The issue allows remote attackers to create user or administrator accounts via a crafted URL in a request to the internal interface.
Recommendations
For Cisco Unified MeetingPlace version 6.0, update to version 6.0.639.3 or later.
For Cisco Unified MeetingPlace version 7.0, apply hotfix 5F or later to version 7.0(2.3).
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Unified Meetingplace