// For flags

CVE-2015-6404

 

Severity Score

4.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Cisco Hosted Collaboration Mediation Fulfillment 10.6(3) does not use RBAC, which allows remote authenticated users to obtain sensitive credential information by leveraging admin access and making SOAP API requests, aka Bug ID CSCuw84374.

Cisco Hosted Collaboration Mediation Fulfillment 10.6(3) no usa RBAC, lo que permite a usuarios remotos autenticados obtener informaciĆ³n sensible de credenciales mediante el aprovechamiento de acceso de administrador y hacer solicitudes API de SOAP, tambiĆ©n conocido como Bug ID CSCuw84374.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-08-17 CVE Reserved
  • 2015-12-15 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Hosted Collaboration Solution
Search vendor "Cisco" for product "Hosted Collaboration Solution"
10.6\(3\)_base
Search vendor "Cisco" for product "Hosted Collaboration Solution" and version "10.6\(3\)_base"
-
Affected