ID

VAR-201502-0153


CVE

CVE-2015-0626


TITLE

Cisco Hosted Collaboration Solution of SOAP Vulnerabilities that gain access rights in the interface

Trust: 0.8

sources: JVNDB: JVNDB-2015-001551

DESCRIPTION

The SOAP interface in Cisco Hosted Collaboration Solution (HCS) allows remote attackers to obtain access to system-management tools via crafted Challenge SOAP calls, aka Bug ID CSCuc38114. Attackers can exploit this issue to gain unauthorized access and obtain sensitive information. This may aid in further attacks. This issue is being tracked by Cisco bug ID CSCuc38114. The solution includes products such as Cisco TelePresence, Customer Collaboration (Contact Center) and Unified Communications to support customers to use collaboration technology in public cloud, private cloud and hybrid cloud models

Trust: 1.98

sources: NVD: CVE-2015-0626 // JVNDB: JVNDB-2015-001551 // BID: 72666 // VULHUB: VHN-78572

AFFECTED PRODUCTS

vendor:ciscomodel:hosted collaboration solutionscope:eqversion: -

Trust: 1.6

vendor:ciscomodel:hosted collaboration solutionscope:eqversion:9.0(1)

Trust: 0.8

sources: JVNDB: JVNDB-2015-001551 // CNNVD: CNNVD-201502-417 // NVD: CVE-2015-0626

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-0626
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-0626
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201502-417
value: MEDIUM

Trust: 0.6

VULHUB: VHN-78572
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-0626
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-78572
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-78572 // JVNDB: JVNDB-2015-001551 // CNNVD: CNNVD-201502-417 // NVD: CVE-2015-0626

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-78572 // JVNDB: JVNDB-2015-001551 // NVD: CVE-2015-0626

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201502-417

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201502-417

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-001551

PATCH

title:Cisco Hosted Collaboration Solution Unauthorized System Access Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0626

Trust: 0.8

title:37515url:http://tools.cisco.com/security/center/viewAlert.x?alertId=37515

Trust: 0.8

sources: JVNDB: JVNDB-2015-001551

EXTERNAL IDS

db:NVDid:CVE-2015-0626

Trust: 2.8

db:JVNDBid:JVNDB-2015-001551

Trust: 0.8

db:CNNVDid:CNNVD-201502-417

Trust: 0.7

db:BIDid:72666

Trust: 0.4

db:VULHUBid:VHN-78572

Trust: 0.1

sources: VULHUB: VHN-78572 // BID: 72666 // JVNDB: JVNDB-2015-001551 // CNNVD: CNNVD-201502-417 // NVD: CVE-2015-0626

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2015-0626

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-0626

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-0626

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-78572 // BID: 72666 // JVNDB: JVNDB-2015-001551 // CNNVD: CNNVD-201502-417 // NVD: CVE-2015-0626

CREDITS

Cisco

Trust: 0.3

sources: BID: 72666

SOURCES

db:VULHUBid:VHN-78572
db:BIDid:72666
db:JVNDBid:JVNDB-2015-001551
db:CNNVDid:CNNVD-201502-417
db:NVDid:CVE-2015-0626

LAST UPDATE DATE

2024-11-23T22:08:10.342000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-78572date:2015-02-19T00:00:00
db:BIDid:72666date:2015-03-19T07:31:00
db:JVNDBid:JVNDB-2015-001551date:2015-02-23T00:00:00
db:CNNVDid:CNNVD-201502-417date:2015-02-26T00:00:00
db:NVDid:CVE-2015-0626date:2024-11-21T02:23:25.987

SOURCES RELEASE DATE

db:VULHUBid:VHN-78572date:2015-02-19T00:00:00
db:BIDid:72666date:2015-02-18T00:00:00
db:JVNDBid:JVNDB-2015-001551date:2015-02-23T00:00:00
db:CNNVDid:CNNVD-201502-417date:2015-02-26T00:00:00
db:NVDid:CVE-2015-0626date:2015-02-19T00:59:02.273