CVE-2015-6425 — NULL Pointer Dereference in Cisco Unified Communications Manager
Severity
5.0MEDIUMNVD
EPSS
0.5%
top 34.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 16
Latest updateMay 17
Description
The WebApplications Identity Management subsystem in Cisco Unified Communications Manager 10.5(0.98000.88) allows remote attackers to cause a denial of service (subsystem outage) via invalid session tokens, aka Bug ID CSCul83786.
CVSS vector
AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9
Affected Packages1 packages
🔴Vulnerability Details
2📋Vendor Advisories
1Cisco▶
Cisco Unified Communications Manager Web Applications Identity Management Subsystem Denial of Service Vulnerability↗2015-12-15