PT-2015-7237 · Cisco+1 · Cisco Telepresence Video Communication Server (Vcs) Expressway+1
Published
2015-12-13
·
Updated
2016-12-07
·
CVE-2015-6413
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco TelePresence Video Communication Server (VCS) Expressway version X8.6
Description
The issue allows remote authenticated users to bypass intended read-only restrictions and upload Tandberg Linux Package (TLP) files by visiting an administrative page.
Recommendations
For Cisco TelePresence Video Communication Server (VCS) Expressway version X8.6, consider restricting access to administrative pages until a fix is available. As a temporary workaround, limit the ability to upload TLP files to prevent potential exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Telepresence Video Communication Server (Vcs) Expressway
Tandberg Linux Package