CVE-2015-4304

The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended access restrictions, and create administrative accounts or read data from arbitrary tenant domains, via a crafted URL, aka Bug IDs CSCus62671 and CSCus62652.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:C/I:C/A:C
ciscoCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
VendorProductVersion
ciscoprime_collaboration_assurance
9.0.0
ciscoprime_collaboration_assurance
9.5.0
ciscoprime_collaboration_assurance
10.0.0
ciscoprime_collaboration_assurance
10.5.0
ciscoprime_collaboration_assurance
10.5.1
ciscoprime_collaboration_assurance
10.6.0
𝑥
= Vulnerable software versions
Common Weakness Enumeration