Search/CVE-2015-4306
CVE

CVE-2015-4306

The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended login-session read restrictions, and impersonate administrators of arbitrary tenant domains, by discovering a session identifier and constructing a crafted URL, aka Bug IDs CSCus88343 and CSCus88334.

CVSS v3.1
EPSS
2.28%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
Connections
2 relationships
Timeline
disclosure → media coverage
Sep 20, 2015
Disclosure — published as a CVE record. · last revised by NVD May 6, 2026