CVE-2010-4304
mediumCVSS v3 Base Score
6.4
AV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS Score
0.3%
Exploitation probability in 30 days
Top 51% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Confidentiality
P
Integrity
P
Availability
None
Published: November 22, 2010 (5651 days ago)
Last Modified: April 29, 2026
Vendor: Cisco
Source: NVD
Vulnerability Report
Generated by CyberWatcher
Description
The web interface in Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115, and 5230; Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway; Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway; and Unified Videoconferencing 3515 Multipoint Control Unit (MCU) uses predictable session IDs based on time values, which makes it easier for remote attackers to hijack sessions via a brute-force attack, aka Bug ID CSCti54048.
CWE
CWE-310Affected Products
cisco unified videoconferencing system 5110 firmwarecisco unified videoconferencing system 5115 firmwarecisco unified videoconferencing system 5110cisco unified videoconferencing system 5115cisco unified videoconferencing system 3515 multipoint control unit firmwarecisco unified videoconferencing system 3522 basic rate interface gateway firmwarecisco unified videoconferencing system 3527 primary rate interface gateway firmwarecisco unified videoconferencing system 3545 firmwarecisco unified videoconferencing system 5230 firmwarecisco unified videoconferencing system 3515 multipoint control unit