CVE-2015-4214
published 2015-06-24CVE-2015-4214: Cisco Unified MeetingPlace 8.6(1.2) and 8.6(1.9) allows remote authenticated users to discover cleartext passwords by reading HTML source code, aka Bug ID…
PriorityP418medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
2.02%
78.9th percentile
Cisco Unified MeetingPlace 8.6(1.2) and 8.6(1.9) allows remote authenticated users to discover cleartext passwords by reading HTML source code, aka Bug ID CSCuu33050.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_meetingplace | — | — |
| cisco | unified_meetingplace | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-54xj-7cwx-cc55: Cisco Unified MeetingPlace 8
ghsa_unreviewed·2022-05-17
CVE-2015-4214 [MEDIUM] CWE-200 GHSA-54xj-7cwx-cc55: Cisco Unified MeetingPlace 8
Cisco Unified MeetingPlace 8.6(1.2) and 8.6(1.9) allows remote authenticated users to discover cleartext passwords by reading HTML source code, aka Bug ID CSCuu33050.
Cisco
Cisco Unified MeetingPlace Plain Text Password Information Disclosure Vulnerability
vendor_cisco·2015-06-23·CVSS 4.0
CVE-2015-4214 [MEDIUM] CWE-200 Cisco Unified MeetingPlace Plain Text Password Information Disclosure Vulnerability
Cisco Unified MeetingPlace Plain Text Password Information Disclosure Vulnerability
A vulnerability in Cisco Unified MeetingPlace could allow an authenticated, remote attacker to view passwords in plain text.
The vulnerability is due to the inclusion of sensitive information in the web page source code of the affected software. An attacker could exploit this vulnerability to view passwords in plain text format.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requirement reduces the likelihood of a successful exploit.
Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-06-24
Published