First published: Sun May 17 2015(Updated: )
Cross-site request forgery (CSRF) vulnerability in Cisco Unified Customer Voice Portal (CVP) 10.5(1) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCut93970.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Customer Voice Portal | =10.5\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0735 has a medium severity rating due to its ability to allow remote attackers to hijack user authentication.
To fix CVE-2015-0735, it is recommended to apply the latest security updates provided by Cisco for Unified Customer Voice Portal 10.5(1).
CVE-2015-0735 can be exploited through cross-site request forgery (CSRF) attacks.
CVE-2015-0735 specifically affects Cisco Unified Customer Voice Portal version 10.5(1).
Yes, CVE-2015-0735 can impact users within a local network if they are exposed to malicious web requests.