ID

VAR-201507-0540


CVE

CVE-2015-4255


TITLE

Cisco TelePresence IP Gateway Device Cross-Site Request Forgery Vulnerability

Trust: 1.2

sources: CNVD: CNVD-2015-04451 // CNNVD: CNNVD-201507-301

DESCRIPTION

Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence IP Gateway devices with software 2.0(3.34) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90734. Vendors have confirmed this vulnerability Bug ID CSCuu90734 It is released as.A third party may be able to hijack the authentication of any user. Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible. This issue is being tracked by Cisco Bug ID CSCuu90734

Trust: 2.52

sources: NVD: CVE-2015-4255 // JVNDB: JVNDB-2015-003547 // CNVD: CNVD-2015-04451 // BID: 75672 // VULHUB: VHN-82216

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2015-04451

AFFECTED PRODUCTS

vendor:ciscomodel:telepresence ip gatewayscope:eqversion:2.0.3.34

Trust: 1.6

vendor:ciscomodel:telepresence ip gateway series softwarescope:eqversion:2.0(3.34)

Trust: 0.8

vendor:ciscomodel:telepresence ip gatewayscope:eqversion:2.0(3.34)

Trust: 0.6

vendor:ciscomodel:telepresence ip gateway seriesscope:eqversion:2.0.3.34

Trust: 0.3

sources: CNVD: CNVD-2015-04451 // BID: 75672 // JVNDB: JVNDB-2015-003547 // CNNVD: CNNVD-201507-301 // NVD: CVE-2015-4255

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-4255
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-4255
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2015-04451
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201507-301
value: MEDIUM

Trust: 0.6

VULHUB: VHN-82216
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-4255
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2015-04451
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-82216
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2015-04451 // VULHUB: VHN-82216 // JVNDB: JVNDB-2015-003547 // CNNVD: CNNVD-201507-301 // NVD: CVE-2015-4255

PROBLEMTYPE DATA

problemtype:CWE-352

Trust: 1.9

sources: VULHUB: VHN-82216 // JVNDB: JVNDB-2015-003547 // NVD: CVE-2015-4255

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201507-301

TYPE

cross-site request forgery

Trust: 0.6

sources: CNNVD: CNNVD-201507-301

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-003547

PATCH

title:39798url:http://tools.cisco.com/security/center/viewAlert.x?alertId=39798

Trust: 0.8

sources: JVNDB: JVNDB-2015-003547

EXTERNAL IDS

db:NVDid:CVE-2015-4255

Trust: 3.4

db:SECTRACKid:1032838

Trust: 1.1

db:BIDid:75672

Trust: 1.0

db:JVNDBid:JVNDB-2015-003547

Trust: 0.8

db:CNNVDid:CNNVD-201507-301

Trust: 0.7

db:CNVDid:CNVD-2015-04451

Trust: 0.6

db:VULHUBid:VHN-82216

Trust: 0.1

sources: CNVD: CNVD-2015-04451 // VULHUB: VHN-82216 // BID: 75672 // JVNDB: JVNDB-2015-003547 // CNNVD: CNNVD-201507-301 // NVD: CVE-2015-4255

REFERENCES

url:http://tools.cisco.com/security/center/viewalert.x?alertid=39798

Trust: 2.6

url:http://www.securitytracker.com/id/1032838

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-4255

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-4255

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: CNVD: CNVD-2015-04451 // VULHUB: VHN-82216 // BID: 75672 // JVNDB: JVNDB-2015-003547 // CNNVD: CNNVD-201507-301 // NVD: CVE-2015-4255

CREDITS

Cisco

Trust: 0.3

sources: BID: 75672

SOURCES

db:CNVDid:CNVD-2015-04451
db:VULHUBid:VHN-82216
db:BIDid:75672
db:JVNDBid:JVNDB-2015-003547
db:CNNVDid:CNNVD-201507-301
db:NVDid:CVE-2015-4255

LAST UPDATE DATE

2025-04-13T23:14:30.995000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-04451date:2015-07-14T00:00:00
db:VULHUBid:VHN-82216date:2016-12-29T00:00:00
db:BIDid:75672date:2015-07-09T00:00:00
db:JVNDBid:JVNDB-2015-003547date:2015-07-14T00:00:00
db:CNNVDid:CNNVD-201507-301date:2015-07-10T00:00:00
db:NVDid:CVE-2015-4255date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:CNVDid:CNVD-2015-04451date:2015-07-14T00:00:00
db:VULHUBid:VHN-82216date:2015-07-10T00:00:00
db:BIDid:75672date:2015-07-09T00:00:00
db:JVNDBid:JVNDB-2015-003547date:2015-07-14T00:00:00
db:CNNVDid:CNNVD-201507-301date:2015-07-10T00:00:00
db:NVDid:CVE-2015-4255date:2015-07-10T00:59:03.057