CVE-2015-6422
published 2015-12-14CVE-2015-6422: The self-service application in Cisco Unified Communications Domain Manager (CUCDM) 10.6(1) allows remote authenticated users to cause a denial of service…
PriorityP417medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
1.87%
76.9th percentile
The self-service application in Cisco Unified Communications Domain Manager (CUCDM) 10.6(1) allows remote authenticated users to cause a denial of service (subapplication outage) via malformed requests, aka Bug ID CSCuu10981.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_domain_manager | — | — |
| cisco | unified_communications_domain_manager | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Domain Manager Denial of Service Vulnerability
vendor_cisco·2015-12-11·CVSS 4.0
CVE-2015-6422 [MEDIUM] CWE-399 Cisco Unified Communications Domain Manager Denial of Service Vulnerability
Cisco Unified Communications Domain Manager Denial of Service Vulnerability
A vulnerability in Cisco Unified Communications Domain Manager (CUCDM) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition.
The vulnerability is due to improper handling of malformed requests by the self-service application on an affected CUCDM device. An authenticated, remote attacker could exploit this vulnerability by sending specific malformed requests to the self-service application on a targeted device. A successful exploit could cause the self-service subapplication of CUCDM to become unavailable, resulting in a DoS condition.
Cisco has not released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This
Cisco
Cisco Unified Communications Domain Manager Denial of Service Vulnerability
vendor_cisco
CVE-2015-6422 Cisco Unified Communications Domain Manager Denial of Service Vulnerability
CVE-2015-6422: Cisco Unified Communications Domain Manager Denial of Service Vulnerability
A vulnerability in Cisco Unified Communications Domain Manager (CUCDM) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper handling of malformed requests by the self-service application on an affected CUCDM device. An authenticated, remote attacker could exploit this vulnerability by sending specific malformed requests to the self-service application on a targeted device. A successful exploit could cause the self-service subapplication of CUCDM to become unavailable, resulting in a DoS condition. Cisco has not released software updates that address this vulnerability.
CWE: CWE-399, CWE-399
Bug IDs: CSCuu10981
GHSA
GHSA-fm2p-mpf3-mr8r: The self-service application in Cisco Unified Communications Domain Manager (CUCDM) 10
ghsa_unreviewed·2022-05-17
CVE-2015-6422 [MEDIUM] GHSA-fm2p-mpf3-mr8r: The self-service application in Cisco Unified Communications Domain Manager (CUCDM) 10
The self-service application in Cisco Unified Communications Domain Manager (CUCDM) 10.6(1) allows remote authenticated users to cause a denial of service (subapplication outage) via malformed requests, aka Bug ID CSCuu10981.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151211-ucdmhttp://www.securityfocus.com/bid/79032http://www.securitytracker.com/id/1034407http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151211-ucdmhttp://www.securityfocus.com/bid/79032http://www.securitytracker.com/id/1034407
2015-12-14
Published