CVE-2015-4229
published 2015-06-30CVE-2015-4229: The web framework in Cisco Unified Communications Domain Manager 8.1(4)ER1 allows remote attackers to obtain sensitive information by visiting a bvsmweb URL…
PriorityP424medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.63%
83.8th percentile
The web framework in Cisco Unified Communications Domain Manager 8.1(4)ER1 allows remote attackers to obtain sensitive information by visiting a bvsmweb URL, aka Bug ID CSCuq22589.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_domain_manager | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rf7x-69fc-g99g: The web framework in Cisco Unified Communications Domain Manager 8
ghsa_unreviewed·2022-05-17
CVE-2015-4229 [MEDIUM] CWE-200 GHSA-rf7x-69fc-g99g: The web framework in Cisco Unified Communications Domain Manager 8
The web framework in Cisco Unified Communications Domain Manager 8.1(4)ER1 allows remote attackers to obtain sensitive information by visiting a bvsmweb URL, aka Bug ID CSCuq22589.
Cisco
Cisco Unified Communications Domain Manager Information Disclosure Vulnerability
vendor_cisco·2015-06-29·CVSS 5.0
CVE-2015-4229 [MEDIUM] CWE-200 Cisco Unified Communications Domain Manager Information Disclosure Vulnerability
Cisco Unified Communications Domain Manager Information Disclosure Vulnerability
A vulnerability in the web framework of Cisco Unified Communications Domain Manager Application Software could allow an unauthenticated, remote attacker to access content in the bvsmweb directory.
The vulnerability is due to insufficient access controls. An attacker could exploit this vulnerability by accessing the affected web page. A successful exploit could allow the attacker to access sensitive information, which could be used to conduct further attacks.
Cisco has confirmed the vulnerability and released software updates.
Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-06-30
Published