PT-2015-1963 · Cisco · Cisco Telepresence Video Communication Server

Published

2015-08-20

·

Updated

2017-01-04

·

CVE-2015-4328

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco TelePresence Video Communication Server versions X8.5.2
Description The issue exists due to insufficient input validation in the software. It allows a remote attacker to execute arbitrary OS commands using a specially crafted HTTP request. This can be achieved by exploiting the improper checking of a user account's read-only attribute, enabling remote authenticated users to perform read or write operations on the Unified Communications lookup page.
Recommendations For version X8.5.2, consider restricting access to the Unified Communications lookup page until a patch is available. As a temporary workaround, limit the execution of arbitrary OS commands by restricting the use of crafted HTTP requests.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-11309
CVE-2015-4328

Affected Products

Cisco Telepresence Video Communication Server