CVE-2015-4314
published 2015-08-20CVE-2015-4314: The System Snapshot feature in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.1 allows remote authenticated users to obtain sensitive…
PriorityP417medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
1.33%
67.7th percentile
The System Snapshot feature in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.1 allows remote authenticated users to obtain sensitive password-hash information by reading the snapshot file, aka Bug ID CSCuv40422.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_video_communication_server_software | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8p99-9wv6-j35h: The System Snapshot feature in Cisco TelePresence Video Communication Server (VCS) Expressway X8
ghsa_unreviewed·2022-05-17
CVE-2015-4314 [MEDIUM] CWE-200 GHSA-8p99-9wv6-j35h: The System Snapshot feature in Cisco TelePresence Video Communication Server (VCS) Expressway X8
The System Snapshot feature in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.1 allows remote authenticated users to obtain sensitive password-hash information by reading the snapshot file, aka Bug ID CSCuv40422.
Cisco
Cisco TelePresence Video Communication Server Expressway Information Disclosure Vulnerability
vendor_cisco·2015-08-12·CVSS 4.0
CVE-2015-4314 [MEDIUM] CWE-200 Cisco TelePresence Video Communication Server Expressway Information Disclosure Vulnerability
Cisco TelePresence Video Communication Server Expressway Information Disclosure Vulnerability
A vulnerability in the System Snapshot of Cisco TelePresence Video Communication Server (VCS) Expressway could allow an authenticated, remote attacker to view sensitive data.
The vulnerability is due to insufficient protection of data at rest. An attacker could exploit this vulnerability by downloading the snapshot file and viewing the password hashes in it. An exploit could allow the attacker to crack the password hashes and use the credentials to launch further attacks.
Cisco has confirmed the vulnerability; however, software updates are not available.
To exploit this vulnerability, an attacker requires authenticated access to the targeted system. Authenticated access may require the attack
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-08-20
Published