CVE-2015-6425
published 2015-12-16CVE-2015-6425: The WebApplications Identity Management subsystem in Cisco Unified Communications Manager 10.5(0.98000.88) allows remote attackers to cause a denial of service…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.37%
82.0th percentile
The WebApplications Identity Management subsystem in Cisco Unified Communications Manager 10.5(0.98000.88) allows remote attackers to cause a denial of service (subsystem outage) via invalid session tokens, aka Bug ID CSCul83786.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager_web_applications_identity_management_subsystem | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.5MEDIUM
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Communications Manager Web Applications Identity Management Subsystem Denial of Service Vulnerability
vendor_cisco·2015-12-15·CVSS 5.0
CVE-2015-6425 [MEDIUM] CWE-399 Cisco Unified Communications Manager Web Applications Identity Management Subsystem Denial of Service Vulnerability
Cisco Unified Communications Manager Web Applications Identity Management Subsystem Denial of Service Vulnerability
A vulnerability in the Identity Management subsystem used by the WebApplications of Cisco Unified Communications Manager (Cisco UCM) software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
The vulnerability is due to invalid session requests. An attacker could exploit this vulnerability by sending invalid session tokens to the subsystem of an affected system. A successful exploit could allow the attacker to cause a DoS condition for a specific application. The affected subsystem would need to be restarted.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not
Cisco
Cisco Unified Communications Manager Web Applications Identity Management Subsystem Denial of Service Vulnerability
vendor_cisco
CVE-2015-6425 Cisco Unified Communications Manager Web Applications Identity Management Subsystem Denial of Service Vulnerability
CVE-2015-6425: Cisco Unified Communications Manager Web Applications Identity Management Subsystem Denial of Service Vulnerability
A vulnerability in the Identity Management subsystem used by the WebApplications of Cisco Unified Communications Manager (Cisco UCM) software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to invalid session requests. An attacker could exploit this vulnerability by sending invalid session tokens to the subsystem of an affected system. A successful exploit could allow the attacker to cause a DoS condition for a specific application. The affected subsystem would need to be restarted. Cisco has released software updates that address this vulnerability.
CWE: CWE-399, CWE-399
Bug IDs: CSCul83786
GHSA
GHSA-h85h-82cj-69hx: The WebApplications Identity Management subsystem in Cisco Unified Communications Manager 10
ghsa_unreviewed·2022-05-17
CVE-2015-6425 [MEDIUM] GHSA-h85h-82cj-69hx: The WebApplications Identity Management subsystem in Cisco Unified Communications Manager 10
The WebApplications Identity Management subsystem in Cisco Unified Communications Manager 10.5(0.98000.88) allows remote attackers to cause a denial of service (subsystem outage) via invalid session tokens, aka Bug ID CSCul83786.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151215-ucmimhttp://www.securityfocus.com/bid/79275http://www.securitytracker.com/id/1034431http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151215-ucmimhttp://www.securityfocus.com/bid/79275http://www.securitytracker.com/id/1034431
2015-12-16
Published