First published: Thu Jul 16 2015(Updated: )
Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Unified Intelligence Center 10.0(1) and 10.6(1) allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCuu94862 and CSCuu97936.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Intelligence Center | =10.0\(1\) | |
Cisco Unified Intelligence Center | =10.6\(1\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4274 is classified as a medium severity vulnerability due to its potential for cross-site request forgery (CSRF).
To fix CVE-2015-4274, update your Cisco Unified Intelligence Center to the latest available version that addresses this vulnerability.
CVE-2015-4274 affects users of Cisco Unified Intelligence Center versions 10.0(1) and 10.6(1).
CVE-2015-4274 is a Cross-site Request Forgery (CSRF) vulnerability that can lead to the hijacking of user authentication.
Attackers exploiting CVE-2015-4274 can hijack the authentication of arbitrary users within the affected web framework.