ID

VAR-201508-0505


CVE

CVE-2015-4297


TITLE

Cisco WebEx Node for MCS Open redirect vulnerability

Trust: 1.4

sources: JVNDB: JVNDB-2015-004354 // CNNVD: CNNVD-201508-385

DESCRIPTION

Open redirect vulnerability in Cisco WebEx Node for Media Convergence Server (MCS) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted HTTP request parameters, aka Bug ID CSCuv32136. Vendors have confirmed this vulnerability Bug ID CSCuv32136 It is released as. Supplementary information : CWE Vulnerability type by CWE-601: URL Redirection to Untrusted Site ( Open redirect ) Has been identified. An attacker can leverage this issue to conduct phishing attacks; other attacks are possible. Cisco WebEx Node for MCS is a set of integrated audio, video and Web conferencing software from Cisco

Trust: 1.98

sources: NVD: CVE-2015-4297 // JVNDB: JVNDB-2015-004354 // BID: 76328 // VULHUB: VHN-82258

AFFECTED PRODUCTS

vendor:ciscomodel:webex node for mcsscope:eqversion: -

Trust: 1.6

vendor:ciscomodel:webex node for mcsscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2015-004354 // CNNVD: CNNVD-201508-385 // NVD: CVE-2015-4297

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-4297
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-4297
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201508-385
value: MEDIUM

Trust: 0.6

VULHUB: VHN-82258
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-4297
severity: MEDIUM
baseScore: 5.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-82258
severity: MEDIUM
baseScore: 5.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-82258 // JVNDB: JVNDB-2015-004354 // CNNVD: CNNVD-201508-385 // NVD: CVE-2015-4297

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

problemtype:CWE-Other

Trust: 0.8

sources: JVNDB: JVNDB-2015-004354 // NVD: CVE-2015-4297

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201508-385

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 76328

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-004354

PATCH

title:40427url:http://tools.cisco.com/security/center/viewAlert.x?alertId=40427

Trust: 0.8

sources: JVNDB: JVNDB-2015-004354

EXTERNAL IDS

db:NVDid:CVE-2015-4297

Trust: 2.8

db:BIDid:76328

Trust: 2.0

db:JVNDBid:JVNDB-2015-004354

Trust: 0.8

db:CNNVDid:CNNVD-201508-385

Trust: 0.7

db:VULHUBid:VHN-82258

Trust: 0.1

sources: VULHUB: VHN-82258 // BID: 76328 // JVNDB: JVNDB-2015-004354 // CNNVD: CNNVD-201508-385 // NVD: CVE-2015-4297

REFERENCES

url:http://www.securityfocus.com/bid/76328

Trust: 1.7

url:http://tools.cisco.com/security/center/viewalert.x?alertid=40427

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-4297

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-4297

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-82258 // BID: 76328 // JVNDB: JVNDB-2015-004354 // CNNVD: CNNVD-201508-385 // NVD: CVE-2015-4297

CREDITS

Cisco

Trust: 0.9

sources: BID: 76328 // CNNVD: CNNVD-201508-385

SOURCES

db:VULHUBid:VHN-82258
db:BIDid:76328
db:JVNDBid:JVNDB-2015-004354
db:CNNVDid:CNNVD-201508-385
db:NVDid:CVE-2015-4297

LAST UPDATE DATE

2024-11-23T23:12:38.070000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-82258date:2016-11-28T00:00:00
db:BIDid:76328date:2015-11-03T19:14:00
db:JVNDBid:JVNDB-2015-004354date:2015-08-25T00:00:00
db:CNNVDid:CNNVD-201508-385date:2015-08-20T00:00:00
db:NVDid:CVE-2015-4297date:2024-11-21T02:30:47.497

SOURCES RELEASE DATE

db:VULHUBid:VHN-82258date:2015-08-19T00:00:00
db:BIDid:76328date:2015-08-12T00:00:00
db:JVNDBid:JVNDB-2015-004354date:2015-08-25T00:00:00
db:CNNVDid:CNNVD-201508-385date:2015-08-18T00:00:00
db:NVDid:CVE-2015-4297date:2015-08-19T14:59:00.140