CVE-2015-4307

The web framework in Cisco Prime Collaboration Provisioning before 11.0 allows remote authenticated users to bypass intended access restrictions and create administrative accounts via a crafted URL, aka Bug ID CSCut64111.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:C/I:C/A:C
ciscoCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
VendorProductVersion
ciscoprime_collaboration_provisioning
9.0.0
ciscoprime_collaboration_provisioning
9.5.0
ciscoprime_collaboration_provisioning
10.0.0
ciscoprime_collaboration_provisioning
10.5.0
ciscoprime_collaboration_provisioning
10.5.1
ciscoprime_collaboration_provisioning
10.6.0
𝑥
= Vulnerable software versions
Common Weakness Enumeration