CVE-2015-4306: High severity cisco prime collaboration assurance vulnerability
The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended login-session read restrictions, and impersonate administrators of arbitrary tenant domains, by discovering a session identifier and constructing a crafted URL, aka Bug IDs CSCus88343 and CSCus88334.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4306?
CVE-2015-4306 has a high severity rating due to its potential for remote authenticated users to impersonate administrators.
How do I fix CVE-2015-4306?
To fix CVE-2015-4306, users should upgrade to a patched version of Cisco Prime Collaboration Assurance beyond 10.5.1.53684-1.
What systems are affected by CVE-2015-4306?
CVE-2015-4306 affects Cisco Prime Collaboration Assurance versions 9.0.0, 9.5.0, 10.0.0, 10.5.0, 10.5.1, and 10.6.0.
What kind of attack can exploit CVE-2015-4306?
CVE-2015-4306 can be exploited through URL manipulation and session identifier discovery to bypass session read restrictions.
Who is impacted by CVE-2015-4306?
Remote authenticated users with access to Cisco Prime Collaboration Assurance may be impacted by CVE-2015-4306.