ID

VAR-201507-0537


CVE

CVE-2015-4252


TITLE

Cisco TelePresence ISDN Gateway Device software cross-site request forgery vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2015-003545

DESCRIPTION

Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence ISDN Gateway devices with software 2.2(1.106) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90724. Vendors have confirmed this vulnerability Bug ID CSCuu90724 It is released as.A third party may be able to hijack the authentication of any user. Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible. This issue is being tracked by Cisco Bug ID CSCuu90724. The solution provides features such as high-definition (HD) video, content sharing and encryption

Trust: 1.98

sources: NVD: CVE-2015-4252 // JVNDB: JVNDB-2015-003545 // BID: 75683 // VULHUB: VHN-82213

AFFECTED PRODUCTS

vendor:ciscomodel:telepresence isdn gw 3241scope:eqversion:2.2\(1.106\)

Trust: 1.6

vendor:ciscomodel:telepresence isdn gw 3241 softwarescope:eqversion:2.2(1.106)

Trust: 0.8

vendor:ciscomodel:telepresence isdn gwscope:eqversion:32412.2(1.106)

Trust: 0.3

sources: BID: 75683 // JVNDB: JVNDB-2015-003545 // CNNVD: CNNVD-201507-299 // NVD: CVE-2015-4252

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-4252
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-4252
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201507-299
value: MEDIUM

Trust: 0.6

VULHUB: VHN-82213
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-4252
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-82213
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-82213 // JVNDB: JVNDB-2015-003545 // CNNVD: CNNVD-201507-299 // NVD: CVE-2015-4252

PROBLEMTYPE DATA

problemtype:CWE-352

Trust: 1.9

sources: VULHUB: VHN-82213 // JVNDB: JVNDB-2015-003545 // NVD: CVE-2015-4252

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201507-299

TYPE

cross-site request forgery

Trust: 0.6

sources: CNNVD: CNNVD-201507-299

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-003545

PATCH

title:39795url:http://tools.cisco.com/security/center/viewAlert.x?alertId=39795

Trust: 0.8

sources: JVNDB: JVNDB-2015-003545

EXTERNAL IDS

db:NVDid:CVE-2015-4252

Trust: 2.8

db:SECTRACKid:1032838

Trust: 1.1

db:JVNDBid:JVNDB-2015-003545

Trust: 0.8

db:CNNVDid:CNNVD-201507-299

Trust: 0.7

db:BIDid:75683

Trust: 0.4

db:VULHUBid:VHN-82213

Trust: 0.1

sources: VULHUB: VHN-82213 // BID: 75683 // JVNDB: JVNDB-2015-003545 // CNNVD: CNNVD-201507-299 // NVD: CVE-2015-4252

REFERENCES

url:http://tools.cisco.com/security/center/viewalert.x?alertid=39795

Trust: 2.0

url:http://www.securitytracker.com/id/1032838

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-4252

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-4252

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-82213 // BID: 75683 // JVNDB: JVNDB-2015-003545 // CNNVD: CNNVD-201507-299 // NVD: CVE-2015-4252

CREDITS

Cisco

Trust: 0.3

sources: BID: 75683

SOURCES

db:VULHUBid:VHN-82213
db:BIDid:75683
db:JVNDBid:JVNDB-2015-003545
db:CNNVDid:CNNVD-201507-299
db:NVDid:CVE-2015-4252

LAST UPDATE DATE

2024-11-23T22:13:24.533000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-82213date:2016-12-29T00:00:00
db:BIDid:75683date:2015-07-09T00:00:00
db:JVNDBid:JVNDB-2015-003545date:2015-07-14T00:00:00
db:CNNVDid:CNNVD-201507-299date:2015-07-10T00:00:00
db:NVDid:CVE-2015-4252date:2024-11-21T02:30:42.627

SOURCES RELEASE DATE

db:VULHUBid:VHN-82213date:2015-07-10T00:00:00
db:BIDid:75683date:2015-07-09T00:00:00
db:JVNDBid:JVNDB-2015-003545date:2015-07-14T00:00:00
db:CNNVDid:CNNVD-201507-299date:2015-07-10T00:00:00
db:NVDid:CVE-2015-4252date:2015-07-10T00:59:00.087