7.5
CVSSv3

CVE-2016-1322

Published: 12/02/2016 Updated: 01/03/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The REST interface in Cisco Spark 2015-07-04 allows remote malicious users to bypass intended access restrictions and create arbitrary user accounts via unspecified web requests, aka Bug ID CSCuv72584.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco spark 2015-07-04_base

Vendor Advisories

A vulnerability in the Representational State Transfer (REST) interface of Cisco Spark could allow an unauthenticated, remote attacker to make changes to an affected system system The vulnerability is due to improper implementation of authorization controls when accessing certain web pages of the application An attacker could exploit this vulne ...