CVE-2015-6409

Description

Cisco Jabber 10.6.x, 11.0.x, and 11.1.x on Windows allows man-in-the-middle attackers to conduct STARTTLS downgrade attacks and trigger cleartext XMPP sessions via unspecified vectors, aka Bug ID CSCuw87419.

Risk Information

Base Score
5.9
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.258

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2015-6409 are affected in Cisco Jabber 10.6(2)Windows
Cisco Jabber STARTTLS Downgrade Vulnerability For Cisco Jabber for MacNCM
Cisco Jabber STARTTLS Downgrade Vulnerability For Cisco Jabber for WindowsNCM
Cisco Jabber STARTTLS Downgrade Vulnerability For Cisco Jabber for iPhoneNCM
Cisco Jabber STARTTLS Downgrade Vulnerability For Cisco Unified Mobile CommunicatorNCM
Cisco Jabber STARTTLS Downgrade Vulnerability For Cisco Unified Communications Manager IM & Presence ServiceNCM
Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-6409)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1705811Security Update for Cisco Jabber for Windows 11.6(1.38147)
PATCH-1705972Security Update for Cisco Jabber for iPhone 11.8(1.250291)
PATCH-1705976Security Update for Cisco Unified Mobile Communicator 11.8(1.250274)
PATCH-1706022Security Update for Cisco Unified Communications Manager IM & Presence Service CUP.11.5(1.12900.25)
PATCH-350863Cisco Jabber (15.1.1) (Manual Upload Required)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234