CVE-2015-0764
published 2015-06-04CVE-2015-0764: Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to read arbitrary files via a crafted resource request, aka Bug ID CSCus95603.
PriorityP432medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.95%
78.0th percentile
Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to read arbitrary files via a crafted resource request, aka Bug ID CSCus95603.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_meetingplace | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified MeetingPlace Arbitrary File Download Vulnerability
vendor_cisco·2015-06-03·CVSS 5.0
CVE-2015-0764 [MEDIUM] CWE-200 Cisco Unified MeetingPlace Arbitrary File Download Vulnerability
Cisco Unified MeetingPlace Arbitrary File Download Vulnerability
A vulnerability in the Cisco Unified MeetingPlace application could allow an unauthenticated, remote attacker to retrieve arbitrary files.
The vulnerability is due to improper handling of requests for resources by an affected device. An unauthenticated, remote attacker could exploit this vulnerability to download arbitrary files from a targeted device. A successful exploit could be used to conduct further attacks.
Cisco has confirmed the vulnerability and released software updates.
Attackers must send requests to vulnerable systems, possibly limiting the potential for exploitation in environments that restrict network access from untrusted networks.
GHSA
GHSA-9v9j-h73g-wgrg: Cisco Unified MeetingPlace 8
ghsa_unreviewed·2022-05-17
CVE-2015-0764 [MEDIUM] CWE-200 GHSA-9v9j-h73g-wgrg: Cisco Unified MeetingPlace 8
Cisco Unified MeetingPlace 8.6(1.9) allows remote attackers to read arbitrary files via a crafted resource request, aka Bug ID CSCus95603.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-06-04
Published