CVE-2014-2115

medium Cisco
CVSS v3 Base Score
6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS Score
0.1%
Exploitation probability in 30 days
Top 66% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
M
Confidentiality
P
Integrity
P
Availability
P
Published: April 4, 2014 (4422 days ago)
Last Modified: May 6, 2026
Vendor: Cisco
Source: NVD

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in CERUserServlet pages in Cisco Emergency Responder (ER) 8.6 and earlier allow remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCun24250.

CWE

CWE-352

Affected Products

cisco emergency responder

References