cbcvebase.
CVE-2015-6404
published 2015-12-15

CVE-2015-6404: Cisco Hosted Collaboration Mediation Fulfillment 10.6(3) does not use RBAC, which allows remote authenticated users to obtain sensitive credential information…

PriorityP416medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
0.95%
57.3th percentile
Cisco Hosted Collaboration Mediation Fulfillment 10.6(3) does not use RBAC, which allows remote authenticated users to obtain sensitive credential information by leveraging admin access and making SOAP API requests, aka Bug ID CSCuw84374.

Affected

2 ranges
VendorProductVersion rangeFixed in
ciscohosted_collaboration_mediation_fulfillment_soap
ciscohosted_collaboration_solution

CVSS provenance

nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.