Описание
The Cisco Unified IP Conference Station 7935 3.2(15) and earlier, and Station 7936 3.3(12) and earlier does not properly handle administrator HTTP sessions, which allows remote attackers to bypass authentication controls via a direct URL request to the administrative HTTP interface for a limited time
Ссылки
- Broken Link
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- PatchVendor Advisory
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- VDB Entry
- Broken Link
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- PatchVendor Advisory
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- VDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 3.2\(15\) (включая)
Одновременно
cpe:2.3:o:cisco:unified_ip_conference_station_7935_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:unified_ip_conference_station_7935:-:*:*:*:*:*:*:*
Конфигурация 2Версия до 3.3\(12\) (включая)
Одновременно
cpe:2.3:o:cisco:unified_ip_conference_station_firmware_7936:*:*:*:*:*:*:*:*
cpe:2.3:h:cisco:unified_ip_conference_station_7936:-:*:*:*:*:*:*:*
EPSS
Процентиль: 90%
0.05729
Низкий
10 Critical
CVSS2
Дефекты
CWE-287
Связанные уязвимости
github
почти 4 года назад
The Cisco Unified IP Conference Station 7935 3.2(15) and earlier, and Station 7936 3.3(12) and earlier does not properly handle administrator HTTP sessions, which allows remote attackers to bypass authentication controls via a direct URL request to the administrative HTTP interface for a limited time
EPSS
Процентиль: 90%
0.05729
Низкий
10 Critical
CVSS2
Дефекты
CWE-287