CVE-2015-0716: CSRF
Published May 7, 2015
·Updated
Cross-site request forgery (CSRF) vulnerability in the CUCReports page in Cisco Unity Connection 11.0(0.98000.225) and 11.0(0.98000.332) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCut33659.
Affected Software
2 affected components
Cisco Unity Connection=11.0\(0.98000.225\)
Cisco Unity Connection=11.0\(0.98000.332\)
Event History
May 7, 2015
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0716?
CVE-2015-0716 has a medium severity rating, indicating potential for exploitation but requiring specific conditions.
2
How do I fix CVE-2015-0716?
To fix CVE-2015-0716, upgrade to the latest versions of Cisco Unity Connection that address this vulnerability.
3
What does CVE-2015-0716 affect?
CVE-2015-0716 affects Cisco Unity Connection versions 11.0(0.98000.225) and 11.0(0.98000.332).
4
What type of vulnerability is CVE-2015-0716?
CVE-2015-0716 is a cross-site request forgery (CSRF) vulnerability.
5
What can attackers do with CVE-2015-0716?
Attackers exploiting CVE-2015-0716 can hijack the authentication of arbitrary users on the affected systems.