CVE-2015-4262

Cisco Unified MeetingPlace Web Conferencing - Unauthenticated Password Reset via Session ID Bypass

Title source: llm
STIX 2.1

Description

The password-change feature in Cisco Unified MeetingPlace Web Conferencing before 8.5(5) MR3 and 8.6 before 8.6(2) does not check the session ID or require entry of the current password, which allows remote attackers to reset arbitrary passwords via a crafted HTTP request, aka Bug ID CSCuu51839.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1033024

Scores

EPSS 0.0284
EPSS Percentile 85.2%

Details

CWE
CWE-255
Status published
Products (17)
cisco/unified_meetingplace_web_conferencing 6.0.417.0
cisco/unified_meetingplace_web_conferencing 6.0_base
cisco/unified_meetingplace_web_conferencing 7.0\(1\)
cisco/unified_meetingplace_web_conferencing 7.0\(2\)
cisco/unified_meetingplace_web_conferencing 7.0\(2\)_sr1
cisco/unified_meetingplace_web_conferencing 7.0\(3\)
cisco/unified_meetingplace_web_conferencing 7.1\(1\)
cisco/unified_meetingplace_web_conferencing 7.1\(2\)
cisco/unified_meetingplace_web_conferencing 8.0\(1\)
cisco/unified_meetingplace_web_conferencing 8.0\(1\)_sr1
... and 7 more
Published Jul 24, 2015
Tracked Since Feb 18, 2026