CVE-2015-6405: CSRF
Published Dec 13, 2015
·Updated
Cross-site request forgery (CSRF) vulnerability in Cisco Emergency Responder 10.5(1) and 10.5(1a) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuv26501.
Affected Software
1 affected component
Cisco Emergency Responder=10.5\(1a\)
Event History
Dec 13, 2015
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6405?
CVE-2015-6405 has a moderate severity level, allowing remote attackers to execute cross-site request forgery attacks.
2
How do I fix CVE-2015-6405?
To fix CVE-2015-6405, update Cisco Emergency Responder to a patched version provided by Cisco.
3
What systems are affected by CVE-2015-6405?
CVE-2015-6405 affects Cisco Emergency Responder versions 10.5(1) and 10.5(1a).
4
What type of attack does CVE-2015-6405 enable?
CVE-2015-6405 enables cross-site request forgery (CSRF) attacks, allowing attackers to impersonate users without their knowledge.
5
Who can exploit CVE-2015-6405?
Remote attackers with knowledge of the vulnerability can exploit CVE-2015-6405 to hijack user sessions in Cisco Emergency Responder.