CVE-2010-4305

medium Cisco
CVSS v3 Base Score
5.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS Score
0.3%
Exploitation probability in 30 days
Top 51% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Confidentiality
P
Integrity
None
Availability
None
Published: November 22, 2010 (5651 days ago)
Last Modified: April 29, 2026
Vendor: Cisco
Source: NVD

Description

Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115, and 5230; Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway; Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway; and Unified Videoconferencing 3515 Multipoint Control Unit (MCU) improperly use cookies for web-interface credentials, which allows remote attackers to obtain sensitive information by reading a (1) cleartext or (2) base64-encoded cleartext cookie, aka Bug ID CSCti54052.

CWE

CWE-310

Affected Products

cisco unified videoconferencing system 5110 firmwarecisco unified videoconferencing system 5115 firmwarecisco unified videoconferencing system 5110cisco unified videoconferencing system 5115cisco unified videoconferencing system 3515 multipoint control unit firmwarecisco unified videoconferencing system 3522 basic rate interface gateway firmwarecisco unified videoconferencing system 3527 primary rate interface gateway firmwarecisco unified videoconferencing system 3545 firmwarecisco unified videoconferencing system 5230 firmwarecisco unified videoconferencing system 3515 multipoint control unit

References