« Volver al listado

CVE-2010-0140

Estado: ModificadaAlta (10)—

Multiple unspecified vulnerabilities in the web server in Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.3, and possibly 5 allow remote attackers to create (1) user or (2) administrator accounts via a crafted URL in a request to the internal interface, aka Bug IDs CSCtc59231 and CSCtd40661.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-0140",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@cisco.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-01-28T20:30:01.480",
  "references": [
    {
      "url": "http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1490b.shtml",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "psirt@cisco.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/37965",
      "source": "psirt@cisco.com"
    },
    {
      "url": "http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1490b.shtml",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/37965",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple unspecified vulnerabilities in the web server in Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.3, and possibly 5 allow remote attackers to create (1) user or (2) administrator accounts via a crafted URL in a request to the internal interface, aka Bug IDs CSCtc59231 and CSCtd40661."
    },
    {
      "lang": "es",
      "value": "Múltiples vulnerabilidades sin especificar en Cisco Unified MeetingPlace v7 en versiones anteriores a v7.0(2.3) arreglo 5F, v6 anteriores a v6.0.639.3, y posiblemente v5  permite a atacantes remotos crear (1) un usuario o (2) cuentas de administrador a través de una URL manipulada en una petición interfaz al interfaz, también conocido con el ID de Bug CSCtc59231 y CSCtd40661."
    }
  ],
  "lastModified": "2026-06-16T23:15:33.310",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cisco:unified_meetingplace:5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1BEEA514-EE52-4BB3-97BD-04246D6F6D7B"
            },
            {
              "criteria": "cpe:2.3:a:cisco:unified_meetingplace:5.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C8F37B63-53F3-4497-BF6D-22E1C1D5D2C3"
            },
            {
              "criteria": "cpe:2.3:a:cisco:unified_meetingplace:5.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A19AF4C2-980E-4FDA-8EA3-372C313C037B"
            },
            {
              "criteria": "cpe:2.3:a:cisco:unified_meetingplace:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "52D721B4-C0B8-4B7C-8C18-6B6B699B48E0"
            },
            {
              "criteria": "cpe:2.3:a:cisco:unified_meetingplace:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F1B3B645-4500-4B63-8D1A-1139537DA522"
            },
            {
              "criteria": "cpe:2.3:a:cisco:unified_meetingplace:7.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5CB60381-CF25-41F1-B54B-CA0F1D77CEC5"
            },
            {
              "criteria": "cpe:2.3:a:cisco:unified_meetingplace:7.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0B746BD5-7783-4510-9260-88E6865277A0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorComment": "Per: http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1490b.shtml\r\n\r\n\r\nAffected Products\r\nVulnerable Products\r\n\r\nCisco Unified MeetingPlace versions 5, 6, and 7 are each affected by at least one of the vulnerabilities described in this document.",
  "sourceIdentifier": "psirt@cisco.com"
}