Access Control Vulnerability in Cisco Unified Communications Manager IM and Presence Service
CVE-2015-4221
Currently unrated
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 26 June 2015
What is CVE-2015-4221?
Cisco Unified Communications Manager IM and Presence Service 9.1(1) contains a vulnerability that fails to adequately restrict access to encrypted passwords. This oversight allows remote attackers to exploit this weakness by navigating to a specific web page to perform a decryption attack on the stored credentials. Successful exploitation may enable the attacker to retrieve cleartext passwords and execute arbitrary commands on the system, posing significant security risks.