CVE-2016-6454
medium
CVSS v3
6.5
CVSS v2
4.3
VIR risk
6.5
Description
A cross-site request forgery (CSRF) vulnerability in the web interface of the Cisco Hosted Collaboration Mediation Fulfillment application could allow an unauthenticated, remote attacker to execute unwanted actions. More Information: CSCva54241. Known Affected Releases: 11.5(1). Known Fixed Releases: 11.5(0.98000.216).
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@cisco.com — https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161026-hcmf
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| cisco | hosted_collaboration_mediation_fulfillment | 10.6\(1\).0 | |
| cisco | hosted_collaboration_mediation_fulfillment | 10.6\(2\).0 | |
| cisco | hosted_collaboration_mediation_fulfillment | 10.6\(3\).0 | |
| cisco | hosted_collaboration_mediation_fulfillment | 11.5\(1\).0 | |
References
CWEs
CWE-352
Verify integrity in audit chain (admin only). AS-IS.