CVE-2016-6426
published 2016-10-05CVE-2016-6426: The j_spring_security_switch_user function in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1)…
PriorityP338high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
1.30%
67.2th percentile
The j_spring_security_switch_user function in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to create user accounts by visiting an unspecified web page, aka Bug IDs CSCuy75027 and CSCuy81653.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_contact_center_express | — | — |
| cisco | unified_contact_center_express | — | — |
| cisco | unified_contact_center_express | — | — |
| cisco | unified_contact_center_express | — | — |
| cisco | unified_intelligence_center | — | — |
| cisco | unified_intelligence_center | — | — |
| cisco | unified_intelligence_center | — | — |
| cisco | unified_intelligence_center | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Intelligence Center (CUIC) Software Unauthenticated User Account Creation Vulnerability
vendor_cisco·2016-10-05·CVSS 4.3
CVE-2016-6426 [MEDIUM] CWE-20 Cisco Unified Intelligence Center (CUIC) Software Unauthenticated User Account Creation Vulnerability
Cisco Unified Intelligence Center (CUIC) Software Unauthenticated User Account Creation Vulnerability
A vulnerability in the j_spring_security_switch_user function of Cisco Unified Intelligence Center (CUIC) Software could allow an unauthenticated, remote attacker to make certain changes to the system.
The vulnerability is due to improper implementation of authorization controls when accessing certain web pages of the application. An attacker could exploit this vulnerability by accessing certain web pages and creating unauthorized user accounts.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/Cisco
Cisco
Cisco Unified Intelligence Center (CUIC) Software Unauthenticated User Account Creation Vulnerability
vendor_cisco
CVE-2016-6426 Cisco Unified Intelligence Center (CUIC) Software Unauthenticated User Account Creation Vulnerability
CVE-2016-6426: Cisco Unified Intelligence Center (CUIC) Software Unauthenticated User Account Creation Vulnerability
A vulnerability in the j_spring_security_switch_user function of Cisco Unified Intelligence Center (CUIC) Software could allow an unauthenticated, remote attacker to make certain changes to the system. The vulnerability is due to improper implementation of authorization controls when accessing certain web pages of the application. An attacker could exploit this vulnerability by accessing certain web pages and creating unauthorized user accounts. Cisco has released software updates that address this vulnerability.
CWE: CWE-20, CWE-20
Bug IDs: CSCuy75027, CSCuy81653
GHSA
GHSA-rc67-hjj5-jc2r: The j_spring_security_switch_user function in Cisco Unified Intelligence Center (CUIC) 8
ghsa_unreviewed·2022-05-17
CVE-2016-6426 [HIGH] CWE-20 GHSA-rc67-hjj5-jc2r: The j_spring_security_switch_user function in Cisco Unified Intelligence Center (CUIC) 8
The j_spring_security_switch_user function in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to create user accounts by visiting an unspecified web page, aka Bug IDs CSCuy75027 and CSCuy81653.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-ucis2http://www.securityfocus.com/bid/93420http://www.securitytracker.com/id/1036952http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-ucis2http://www.securityfocus.com/bid/93420http://www.securitytracker.com/id/1036952
2016-10-05
Published