Cross-Site Request Forgery Vulnerability in Cisco TelePresence IP Gateway Devices
CVE-2015-4255

Currently unrated

Key Information:

Vendor
Cisco
Vendor
CVE Published:
10 July 2015

Summary

A Cross-Site Request Forgery (CSRF) vulnerability exists in Cisco TelePresence IP Gateway devices using software version 2.0(3.34). This vulnerability allows remote attackers to exploit the authentication process, potentially hijacking user sessions. By sending a crafted request to the affected devices, attackers can manipulate user sessions without the user's knowledge, leading to unauthorized actions being performed on their behalf. Protection measures should be implemented promptly to mitigate this security risk.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.