MEDIUM · 4.0

CVE-2015-4221

Cisco Unified Communications Manager IM and Presence Service 9.1(1) does not properly restrict access to encrypted passwords, which allows remote attackers to determine cleartext passwords, and conseq...

Vulnerability Description

Cisco Unified Communications Manager IM and Presence Service 9.1(1) does not properly restrict access to encrypted passwords, which allows remote attackers to determine cleartext passwords, and consequently execute arbitrary commands, by visiting an unspecified web page and then conducting a decryption attack, aka Bug ID CSCuq46194.

CVSS Score

4.0

MEDIUM

AV:N/AC:L/Au:S/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
CiscoUnified Communications Manager Im And Presence Service9.1\(1\)

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-4221?

CVE-2015-4221 is a vulnerability with a CVSS score of 4.0 (MEDIUM). Cisco Unified Communications Manager IM and Presence Service 9.1(1) does not properly restrict access to encrypted passwords, which allows remote attackers to determine cleartext passwords, and conseq...

How severe is CVE-2015-4221?

CVE-2015-4221 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-4221?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Unified Communications Manager Im And Presence Service.