cbcvebase.
CVE-2015-6410
published 2015-12-14

CVE-2015-6410: The Mobile and Remote Access (MRA) services implementation in Cisco Unified Communications Manager mishandles edge-device identity validation, which allows…

PriorityP425medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
1.68%
74.3th percentile
The Mobile and Remote Access (MRA) services implementation in Cisco Unified Communications Manager mishandles edge-device identity validation, which allows remote attackers to bypass intended call-reception and call-setup restrictions by spoofing a user, aka Bug ID CSCuu97283.

Affected

3 ranges
VendorProductVersion rangeFixed in
ciscotelepresence_video_communication_server_software
ciscounified_communications_manager_mobile_and
wouter_verhelstnbd>= 0 < 1:3.7-1ubuntu0.11:3.7-1ubuntu0.1

CVSS provenance

nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv7.5HIGH
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.