CVE-2015-6425NULL Pointer Dereference in Cisco Unified Communications Manager

Severity
5.0MEDIUMNVD
EPSS
0.5%
top 34.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 16
Latest updateMay 17

Description

The WebApplications Identity Management subsystem in Cisco Unified Communications Manager 10.5(0.98000.88) allows remote attackers to cause a denial of service (subsystem outage) via invalid session tokens, aka Bug ID CSCul83786.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

NVDcisco/unified_communications_manager10.5\(0.98000.88\)

🔴Vulnerability Details

2
GHSA
GHSA-h85h-82cj-69hx: The WebApplications Identity Management subsystem in Cisco Unified Communications Manager 102022-05-17
CVEList
CVE-2015-6425: The WebApplications Identity Management subsystem in Cisco Unified Communications Manager 102015-12-16

📋Vendor Advisories

1
Cisco
Cisco Unified Communications Manager Web Applications Identity Management Subsystem Denial of Service Vulnerability2015-12-15
CVE-2015-6425 — NULL Pointer Dereference in Cisco | cvebase