PT-2015-7238 · Cisco · Cisco Telepresence Video Communication Server

Published

2015-12-13

·

Updated

2016-12-07

·

CVE-2015-6414

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco TelePresence Video Communication Server (VCS) version X8.6
Description The issue allows local users to defeat cryptographic protection mechanisms by leveraging knowledge of an encryption key from another installation, as the same encryption key is used across different customers' installations.
Recommendations For Cisco TelePresence Video Communication Server (VCS) version X8.6, consider changing the encryption key to a unique value for each installation to prevent exploitation. As a temporary workaround, restrict access to the system to minimize the risk of local users leveraging knowledge of the encryption key.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-6414

Affected Products

Cisco Telepresence Video Communication Server