CVE-2015-4262
Cisco Unified MeetingPlace Web Conferencing - Unauthenticated Password Reset via Session ID Bypass
Title source: llmDescription
The password-change feature in Cisco Unified MeetingPlace Web Conferencing before 8.5(5) MR3 and 8.6 before 8.6(2) does not check the session ID or require entry of the current password, which allows remote attackers to reset arbitrary passwords via a crafted HTTP request, aka Bug ID CSCuu51839.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
x_refsource_cisco
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150722-mp
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1033024
Scores
EPSS
0.0284
EPSS Percentile
85.2%
Details
CWE
CWE-255
Status
published
Products (17)
cisco/unified_meetingplace_web_conferencing
6.0.417.0
cisco/unified_meetingplace_web_conferencing
6.0_base
cisco/unified_meetingplace_web_conferencing
7.0\(1\)
cisco/unified_meetingplace_web_conferencing
7.0\(2\)
cisco/unified_meetingplace_web_conferencing
7.0\(2\)_sr1
cisco/unified_meetingplace_web_conferencing
7.0\(3\)
cisco/unified_meetingplace_web_conferencing
7.1\(1\)
cisco/unified_meetingplace_web_conferencing
7.1\(2\)
cisco/unified_meetingplace_web_conferencing
8.0\(1\)
cisco/unified_meetingplace_web_conferencing
8.0\(1\)_sr1
... and 7 more
Published
Jul 24, 2015
Tracked Since
Feb 18, 2026