Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-6445

Опубликовано: 27 окт. 2016
Источник: nvd
CVSS3: 9.1
CVSS2: 6.4
EPSS Низкий

Описание

A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of the Cisco Meeting Server (CMS) before 2.0.6 and Acano Server before 1.8.18 and 1.9.x before 1.9.6 could allow an unauthenticated, remote attacker to masquerade as a legitimate user. This vulnerability is due to the XMPP service incorrectly processing a deprecated authentication scheme. A successful exploit could allow an attacker to access the system as another user.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:meeting_server:1.8.15:*:*:*:*:*:*:*
cpe:2.3:a:cisco:meeting_server:1.8_base:*:*:*:*:*:*:*
cpe:2.3:a:cisco:meeting_server:1.9.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:meeting_server:1.9.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:meeting_server:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:meeting_server:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:meeting_server:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:cisco:meeting_server:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:cisco:meeting_server:2.0.5:*:*:*:*:*:*:*

EPSS

Процентиль: 73%
0.0077
Низкий

9.1 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 9.1
github
больше 3 лет назад

A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of the Cisco Meeting Server (CMS) before 2.0.6 and Acano Server before 1.8.18 and 1.9.x before 1.9.6 could allow an unauthenticated, remote attacker to masquerade as a legitimate user. This vulnerability is due to the XMPP service incorrectly processing a deprecated authentication scheme. A successful exploit could allow an attacker to access the system as another user.

EPSS

Процентиль: 73%
0.0077
Низкий

9.1 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-20