Vulnslist

find the latest Cisco vulnerabilities

Cisco IP Communicator Web Access Denial of Service Vulnerability

Cisco-SA-20150707-CVE-2015-4240 · Medium · Published · Updated

A vulnerability in the web interface of Cisco IP Communicator could allow an unauthenticated, remote attacker to take the web service offline.   The vulnerability is due to access of a specific HTTP URL. An attacker could exploit this vulnerability by sending an HTTP GET request to the specific URL. A successful exploit could allow the attacker to take the web service offline, resulting in a denial of service (DoS) condition. Cisco has confirmed the vulnerability and released software updates. To exploit this vulnerability, an attacker may need to gather additional information about the targeted device, such as whether the device has web access enabled. Web access must be enabled for a successful exploit. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Workarounds

Administrators are advised to apply the appropriate updates.

Administrators are advised to allow only trusted users to have network access.

Administrators are advised to monitor affected systems.

CVEsCVE-2015-4240
Cisco Bug IDsCSCuu37656
CVSS ScoreBase 5.0
Base 5.0 AV:N/AC:L/Au:N/C:N/I:N/A:P/E:F/RL:OF/RC:C
Product Names From Source
Cisco IP Communicator

Related Products

Product CVE Evidence
Cisco IP Communicator CVE-2015-4240 Cisco OpenVuln