Vulnerability Name: | CVE-2015-4274 (CCN-104807) | ||||||||
Assigned: | 2015-07-15 | ||||||||
Published: | 2015-07-15 | ||||||||
Updated: | 2017-09-22 | ||||||||
Summary: | Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Unified Intelligence Center 10.0(1) and 10.6(1) allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCuu94862 and CSCuu97936. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
4.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-352 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2015-4274 Source: CCN Type: Cisco Vulnerability Alert 39920 Cisco Unified Intelligence Center Cross-Site Request Forgery Vulnerability Source: CISCO Type: Vendor Advisory 20150715 Cisco Unified Intelligence Center Cross-Site Request Forgery Vulnerability Source: SECTRACK Type: UNKNOWN 1032962 Source: XF Type: UNKNOWN cisco-unified-cve20154274-csrf(104807) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |