10
CVSSv2

CVE-2015-4262

Published: 24/07/2015 Updated: 21/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The password-change feature in Cisco Unified MeetingPlace Web Conferencing prior to 8.5(5) MR3 and 8.6 prior to 8.6(2) does not check the session ID or require entry of the current password, which allows remote malicious users to reset arbitrary passwords via a crafted HTTP request, aka Bug ID CSCuu51839.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified meetingplace web conferencing 6.0.417.0

cisco unified meetingplace web conferencing 6.0_base

cisco unified meetingplace web conferencing 8.5\\(3\\)

cisco unified meetingplace web conferencing 7.0\\(2\\)_sr1

cisco unified meetingplace web conferencing 7.0\\(2\\)

cisco unified meetingplace web conferencing 8.5\\(1\\)

cisco unified meetingplace web conferencing 8.0\\(1\\)

cisco unified meetingplace web conferencing 8.5\\(2\\)_sr2

cisco unified meetingplace web conferencing 8.0\\(2\\)

cisco unified meetingplace web conferencing 8.0\\(1\\)_sr1

cisco unified meetingplace web conferencing 8.5\\(4\\)

cisco unified meetingplace web conferencing 7.0\\(1\\)

cisco unified meetingplace web conferencing 7.1\\(1\\)

cisco unified meetingplace web conferencing 7.1\\(2\\)

cisco unified meetingplace web conferencing 7.0\\(3\\)

cisco unified meetingplace web conferencing 8.5\\(2\\)_sr1

cisco unified meetingplace web conferencing 8.5\\(2\\)