CVE-2015-4306

The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended login-session read restrictions, and impersonate administrators of arbitrary tenant domains, by discovering a session identifier and constructing a crafted URL, aka Bug IDs CSCus88343 and CSCus88334.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.5 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:C/I:C/A:C
ciscoCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
VendorProductVersion
ciscoprime_collaboration_assurance
9.0.0
ciscoprime_collaboration_assurance
9.5.0
ciscoprime_collaboration_assurance
10.0.0
ciscoprime_collaboration_assurance
10.5.0
ciscoprime_collaboration_assurance
10.5.1
ciscoprime_collaboration_assurance
10.6.0
𝑥
= Vulnerable software versions
Common Weakness Enumeration