First published: Sun Dec 13 2015(Updated: )
Cross-site request forgery (CSRF) vulnerability in Cisco Emergency Responder 10.5(1) and 10.5(1a) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuv26501.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Emergency Responder | =10.5\(1a\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6405 has a moderate severity level, allowing remote attackers to execute cross-site request forgery attacks.
To fix CVE-2015-6405, update Cisco Emergency Responder to a patched version provided by Cisco.
CVE-2015-6405 affects Cisco Emergency Responder versions 10.5(1) and 10.5(1a).
CVE-2015-6405 enables cross-site request forgery (CSRF) attacks, allowing attackers to impersonate users without their knowledge.
Remote attackers with knowledge of the vulnerability can exploit CVE-2015-6405 to hijack user sessions in Cisco Emergency Responder.