Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5vv7-4p3j-cg3r

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Cisco Unified IP Conference Station 7935 3.2(15) and earlier, and Station 7936 3.3(12) and earlier does not properly handle administrator HTTP sessions, which allows remote attackers to bypass authentication controls via a direct URL request to the administrative HTTP interface for a limited time

The Cisco Unified IP Conference Station 7935 3.2(15) and earlier, and Station 7936 3.3(12) and earlier does not properly handle administrator HTTP sessions, which allows remote attackers to bypass authentication controls via a direct URL request to the administrative HTTP interface for a limited time

EPSS

Процентиль: 90%
0.05729
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
почти 19 лет назад

The Cisco Unified IP Conference Station 7935 3.2(15) and earlier, and Station 7936 3.3(12) and earlier does not properly handle administrator HTTP sessions, which allows remote attackers to bypass authentication controls via a direct URL request to the administrative HTTP interface for a limited time

EPSS

Процентиль: 90%
0.05729
Низкий

Дефекты

CWE-287