PT-2015-7238 · Cisco · Cisco Telepresence Video Communication Server

Publicado

2015-12-13

·

Atualizado

2016-12-07

·

CVE-2015-6414

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco TelePresence Video Communication Server (VCS) version X8.6
Description The issue allows local users to defeat cryptographic protection mechanisms by leveraging knowledge of an encryption key from another installation, as the same encryption key is used across different customers' installations.
Recommendations For Cisco TelePresence Video Communication Server (VCS) version X8.6, consider changing the encryption key to a unique value for each installation to prevent exploitation. As a temporary workaround, restrict access to the system to minimize the risk of local users leveraging knowledge of the encryption key.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-6414

Produtos afetados

Cisco Telepresence Video Communication Server