CVE-2015-4221: Medium severity cisco unified communications manager im and presence vulnerability
Cisco Unified Communications Manager IM and Presence Service 9.1(1) does not properly restrict access to encrypted passwords, which allows remote attackers to determine cleartext passwords, and consequently execute arbitrary commands, by visiting an unspecified web page and then conducting a decryption attack, aka Bug ID CSCuq46194.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4221?
CVE-2015-4221 is classified as a high severity vulnerability due to its potential to allow remote attackers to capture cleartext passwords.
How do I fix CVE-2015-4221?
To fix CVE-2015-4221, upgrade to a patched version of Cisco Unified Communications Manager IM and Presence Service that addresses the issue.
What systems are affected by CVE-2015-4221?
CVE-2015-4221 affects Cisco Unified Communications Manager IM and Presence Service version 9.1(1).
What type of attack does CVE-2015-4221 enable?
CVE-2015-4221 enables remote attackers to determine cleartext passwords and potentially execute arbitrary commands.
Is CVE-2015-4221 a configuration issue?
CVE-2015-4221 is not strictly a configuration issue but rather a vulnerability in the software's handling of encrypted passwords.