CVE-2018-15401: Cisco Hosted Collaboration Mediation Fulfillment Cross-Site Request Forgery Vulnerability
A vulnerability in the web-based management interface of Cisco Hosted Collaboration Mediation Fulfillment could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions on an affected system via a web browser and with the privileges of the user.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15401?
CVE-2018-15401 is a vulnerability in the web-based management interface of Cisco Hosted Collaboration Mediation Fulfillment that allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system.
How severe is CVE-2018-15401?
CVE-2018-15401 has a severity rating of medium, with a severity value of 6.5.
How can an attacker exploit CVE-2018-15401?
An attacker can exploit CVE-2018-15401 by tricking a user into clicking on a specially crafted link or visiting a malicious website, which triggers a CSRF attack and allows the attacker to perform unauthorized actions on the system.
Which versions of Cisco Hosted Collaboration Mediation Fulfillment are affected by CVE-2018-15401?
Versions 11.5(2), 11.5(3), and 12.5(1) of Cisco Hosted Collaboration Mediation Fulfillment are affected by CVE-2018-15401.
Is there a fix for CVE-2018-15401?
Yes, Cisco has released a security advisory with mitigation measures for CVE-2018-15401. It is recommended to apply the necessary patches or updates provided by Cisco to address this vulnerability.