CVE-2015-4319
published 2015-08-20CVE-2015-4319: The password-change feature in the administrative web interface in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.1 improperly performs…
PriorityP433medium5.5CVSS 2.0
AVNACLAuSCNIPAP
EPSS
2.41%
82.2th percentile
The password-change feature in the administrative web interface in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.1 improperly performs authorization, which allows remote authenticated users to reset arbitrary active-user passwords via unspecified vectors, aka Bug ID CSCuv12338.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_video_communication_server_software | — | — |
CVSS provenance
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
vendor_cisco5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c273-jjf4-fr9f: The password-change feature in the administrative web interface in Cisco TelePresence Video Communication Server (VCS) Expressway X8
ghsa_unreviewed·2022-05-17
CVE-2015-4319 [MEDIUM] GHSA-c273-jjf4-fr9f: The password-change feature in the administrative web interface in Cisco TelePresence Video Communication Server (VCS) Expressway X8
The password-change feature in the administrative web interface in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.1 improperly performs authorization, which allows remote authenticated users to reset arbitrary active-user passwords via unspecified vectors, aka Bug ID CSCuv12338.
Cisco
Cisco TelePresence Video Communication Server Expressway Access Vulnerability
vendor_cisco·2015-08-14·CVSS 5.5
CVE-2015-4319 [MEDIUM] CWE-255 Cisco TelePresence Video Communication Server Expressway Access Vulnerability
Cisco TelePresence Video Communication Server Expressway Access Vulnerability
A vulnerability in the Password Change functionality in the Administrative Web Interface of the Cisco TelePresence Video Communication Server (VCS) Expressway could allow an authenticated, remote attacker to make unauthorized changes to user passwords.
The vulnerability is due to insufficient enforcement in the authorization process. An attacker could exploit this vulnerability by sending a specially crafted packet to the target device. An exploit could allow the attacker to change the password of active users to conduct further attacks.
Cisco has confirmed the vulnerability and software updates are available.
An authenticated, remote attacker could utilize this vulnerability by sending a specially crafted p
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-08-20
Published