ID

VAR-201502-0136


CVE

CVE-2015-0602


TITLE

Cisco Unified IP Phones 9900 Series Information Disclosure Vulnerability

Trust: 1.2

sources: CNVD: CNVD-2015-00922 // CNNVD: CNNVD-201502-093

DESCRIPTION

The mobility extension on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to obtain sensitive information by sniffing the network, aka Bug ID CSCuq12117. Vendors have confirmed this vulnerability Bug ID CSCuq12117 It is released as.If a third party intercepts the network, important information may be obtained. The device provides voice, video and other functions. A remote attacker exploited the vulnerability to gain sensitive information by sniffing the network. This may aid in further attacks. This issue is tracked by Cisco Bug ID CSCuq12117

Trust: 2.52

sources: NVD: CVE-2015-0602 // JVNDB: JVNDB-2015-001526 // CNVD: CNVD-2015-00922 // BID: 72482 // VULHUB: VHN-78548

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2015-00922

AFFECTED PRODUCTS

vendor:ciscomodel:unified ip phones 9900 seriesscope:lteversion:9.4\(.1\)

Trust: 1.0

vendor:ciscomodel:unified ip phone 9900 seriesscope:lteversion:9.4(.1)

Trust: 0.8

vendor:ciscomodel:unified ip phone 9951scope: - version: -

Trust: 0.8

vendor:ciscomodel:unified ip phone 9971scope: - version: -

Trust: 0.8

vendor:ciscomodel:unified ip phones seriesscope:eqversion:9900

Trust: 0.6

vendor:ciscomodel:unified ip phones 9900 seriesscope:eqversion:9.4\(.1\)

Trust: 0.6

vendor:ciscomodel:unified ip phones seriesscope:eqversion:99000

Trust: 0.3

sources: CNVD: CNVD-2015-00922 // BID: 72482 // JVNDB: JVNDB-2015-001526 // CNNVD: CNNVD-201502-093 // NVD: CVE-2015-0602

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-0602
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-0602
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2015-00922
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201502-093
value: MEDIUM

Trust: 0.6

VULHUB: VHN-78548
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-0602
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2015-00922
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-78548
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2015-00922 // VULHUB: VHN-78548 // JVNDB: JVNDB-2015-001526 // CNNVD: CNNVD-201502-093 // NVD: CVE-2015-0602

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.9

sources: VULHUB: VHN-78548 // JVNDB: JVNDB-2015-001526 // NVD: CVE-2015-0602

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201502-093

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201502-093

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-001526

PATCH

title:Cisco Unified IP Phone 9900 Series Data Disclosure Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0602

Trust: 0.8

title:37342url:http://tools.cisco.com/security/center/viewAlert.x?alertId=37342

Trust: 0.8

sources: JVNDB: JVNDB-2015-001526

EXTERNAL IDS

db:NVDid:CVE-2015-0602

Trust: 3.4

db:BIDid:72482

Trust: 2.6

db:JVNDBid:JVNDB-2015-001526

Trust: 0.8

db:CNNVDid:CNNVD-201502-093

Trust: 0.7

db:CNVDid:CNVD-2015-00922

Trust: 0.6

db:VULHUBid:VHN-78548

Trust: 0.1

sources: CNVD: CNVD-2015-00922 // VULHUB: VHN-78548 // BID: 72482 // JVNDB: JVNDB-2015-001526 // CNNVD: CNNVD-201502-093 // NVD: CVE-2015-0602

REFERENCES

url:http://www.securityfocus.com/bid/72482

Trust: 2.3

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2015-0602

Trust: 1.7

url:http://tools.cisco.com/security/center/viewalert.x?alertid=37342

Trust: 1.7

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/100615

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-0602

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-0602

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

url:http://www.cisco.com/en/us/products/ps10453/index.html

Trust: 0.3

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2015-0602

Trust: 0.3

sources: CNVD: CNVD-2015-00922 // VULHUB: VHN-78548 // BID: 72482 // JVNDB: JVNDB-2015-001526 // CNNVD: CNNVD-201502-093 // NVD: CVE-2015-0602

CREDITS

Cisco

Trust: 0.9

sources: BID: 72482 // CNNVD: CNNVD-201502-093

SOURCES

db:CNVDid:CNVD-2015-00922
db:VULHUBid:VHN-78548
db:BIDid:72482
db:JVNDBid:JVNDB-2015-001526
db:CNNVDid:CNNVD-201502-093
db:NVDid:CVE-2015-0602

LAST UPDATE DATE

2024-11-23T23:09:19.794000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-00922date:2015-02-06T00:00:00
db:VULHUBid:VHN-78548date:2017-09-08T00:00:00
db:BIDid:72482date:2015-02-03T00:00:00
db:JVNDBid:JVNDB-2015-001526date:2015-02-19T00:00:00
db:CNNVDid:CNNVD-201502-093date:2015-02-09T00:00:00
db:NVDid:CVE-2015-0602date:2024-11-21T02:23:23.540

SOURCES RELEASE DATE

db:CNVDid:CNVD-2015-00922date:2015-02-06T00:00:00
db:VULHUBid:VHN-78548date:2015-02-07T00:00:00
db:BIDid:72482date:2015-02-03T00:00:00
db:JVNDBid:JVNDB-2015-001526date:2015-02-19T00:00:00
db:CNNVDid:CNNVD-201502-093date:2015-02-05T00:00:00
db:NVDid:CVE-2015-0602date:2015-02-07T15:59:08.207