CVE-2016-6468: CSRF
A vulnerability in the web-based management interface of Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. More Information: CSCvb06663. Known Affected Releases: 11.5(1.10000.4). Known Fixed Releases: 12.0(0.98000.14).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6468?
CVE-2016-6468 has a medium severity rating, indicating a moderate level of risk to affected systems.
How do I fix CVE-2016-6468?
To fix CVE-2016-6468, upgrade to a fixed version of Cisco Emergency Responder, specifically versions later than 11.5(1.10000.4).
What type of attack does CVE-2016-6468 allow?
CVE-2016-6468 allows an unauthenticated remote attacker to perform cross-site request forgery (CSRF) attacks.
Which versions of Cisco Emergency Responder are affected by CVE-2016-6468?
CVE-2016-6468 affects Cisco Emergency Responder version 11.5(1.10000.4) and potentially other versions in the 11.5 release series.
Can CVE-2016-6468 be exploited without authentication?
Yes, CVE-2016-6468 can be exploited by unauthenticated attackers, making it a significant risk.