PT-2015-1963 · Cisco · Cisco Telepresence Video Communication Server
Published
2015-08-20
·
Updated
2017-01-04
·
CVE-2015-4328
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco TelePresence Video Communication Server versions X8.5.2
Description
The issue exists due to insufficient input validation in the software. It allows a remote attacker to execute arbitrary OS commands using a specially crafted HTTP request. This can be achieved by exploiting the improper checking of a user account's read-only attribute, enabling remote authenticated users to perform read or write operations on the Unified Communications lookup page.
Recommendations
For version X8.5.2, consider restricting access to the Unified Communications lookup page until a patch is available. As a temporary workaround, limit the execution of arbitrary OS commands by restricting the use of crafted HTTP requests.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Telepresence Video Communication Server