CVE-2015-4306
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
20/09/2015
Last modified:
12/04/2025
Description
The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended login-session read restrictions, and impersonate administrators of arbitrary tenant domains, by discovering a session identifier and constructing a crafted URL, aka Bug IDs CSCus88343 and CSCus88334.
Impact
Base Score 2.0
8.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:cisco:prime_collaboration_assurance:9.0.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:prime_collaboration_assurance:9.5.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:prime_collaboration_assurance:10.0.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:prime_collaboration_assurance:10.5.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:prime_collaboration_assurance:10.5.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:prime_collaboration_assurance:10.6.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page