Vulnslist

find the latest Cisco vulnerabilities

Cisco Prime Collaboration Assurance Web Interface Denial of Service Vulnerability

Cisco-SA-20150716-CVE-2015-4280 · Medium · Published · Updated

A vulnerability in the web interface of Cisco Prime Collaboration Assurance could allow a remote, unauthenticated attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper handling of a crafted HTTP request. An unauthenticated, remote attacker could exploit this vulnerability by sending a crafted HTTP request to a targeted system. A successful exploit could cause the web interface on a targeted system to become unresponsive, resulting in a DoS condition. Cisco has confirmed the vulnerability and released software updates. To exploit this vulnerability, an attacker must be able to send a crafted HTTP request to the targeted device, making exploitation more difficult in environments that restrict network access to untrusted sources.

Workarounds

Administrators are advised to apply the appropriate updates.

Administrators are advised to allow only trusted users to have network access.

Administrators are advised to monitor affected systems.

CVEsCVE-2015-4280
Cisco Bug IDsCSCum38844
CVSS ScoreBase 5.0
Base 5.0 AV:N/AC:L/Au:N/C:N/I:N/A:P/E:F/RL:OF/RC:C
Product Names From Source
Cisco Prime Collaboration

CSAF Product Statuses

Product Status Source CVE Rows
Cisco Prime Collaboration known_affected cisco_csaf CVE-2015-4280 1

Related Products

Product CVE Evidence
Cisco Prime Collaboration CVE-2015-4280 Cisco OpenVuln
Cisco Prime Collaboration Assurance CVE-2015-4280 Cisco OpenVuln