CVE-2015-4262

critical
Published 2015-07-24 · Modified 2026-05-06
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

The password-change feature in Cisco Unified MeetingPlace Web Conferencing before 8.5(5) MR3 and 8.6 before 8.6(2) does not check the session ID or require entry of the current password, which allows remote attackers to reset arbitrary passwords via a crafted HTTP request, aka Bug ID CSCuu51839.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@cisco.com — http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150722-mp

Application impact

VendorProductVersionsFixed
ciscounified_meetingplace_web_conferencing6.0.417.0
ciscounified_meetingplace_web_conferencing6.0_base
ciscounified_meetingplace_web_conferencing7.0\(1\)
ciscounified_meetingplace_web_conferencing7.0\(2\)
ciscounified_meetingplace_web_conferencing7.0\(2\)_sr1
ciscounified_meetingplace_web_conferencing7.0\(3\)
ciscounified_meetingplace_web_conferencing7.1\(1\)
ciscounified_meetingplace_web_conferencing7.1\(2\)
ciscounified_meetingplace_web_conferencing8.0\(1\)
ciscounified_meetingplace_web_conferencing8.0\(1\)_sr1
ciscounified_meetingplace_web_conferencing8.0\(2\)
ciscounified_meetingplace_web_conferencing8.5\(1\)
ciscounified_meetingplace_web_conferencing8.5\(2\)
ciscounified_meetingplace_web_conferencing8.5\(2\)_sr1
ciscounified_meetingplace_web_conferencing8.5\(2\)_sr2
ciscounified_meetingplace_web_conferencing8.5\(3\)
ciscounified_meetingplace_web_conferencing8.5\(4\)

References

CWEs

CWE-255

Verify integrity in audit chain (admin only). AS-IS.