CVE-2015-4320
published 2015-08-20CVE-2015-4320: The Configuration Log File component in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows remote authenticated users to obtain…
PriorityP416medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
1.65%
73.8th percentile
The Configuration Log File component in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows remote authenticated users to obtain sensitive information by reading a log file, aka Bug ID CSCuv12340.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_video_communication_server_software | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4642-8q68-7rgp: The Configuration Log File component in Cisco TelePresence Video Communication Server (VCS) Expressway X8
ghsa_unreviewed·2022-05-17
CVE-2015-4320 [MEDIUM] CWE-200 GHSA-4642-8q68-7rgp: The Configuration Log File component in Cisco TelePresence Video Communication Server (VCS) Expressway X8
The Configuration Log File component in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows remote authenticated users to obtain sensitive information by reading a log file, aka Bug ID CSCuv12340.
Cisco
Cisco TelePresence Video Communication Server Expressway Information Disclosure Vulnerability
vendor_cisco·2015-08-13·CVSS 4.0
CVE-2015-4320 [MEDIUM] CWE-200 Cisco TelePresence Video Communication Server Expressway Information Disclosure Vulnerability
Cisco TelePresence Video Communication Server Expressway Information Disclosure Vulnerability
A vulnerability in Configuration Log File of the Cisco TelePresence Video Communication Server (VCS) Expressway could allow an authenticated, remote attacker to obtain sensitive information stored on an affected system.
The vulnerability is due to the inclusion of sensitive information in certain log files. An attacker could exploit this vulnerability by viewing the sensitive information in the vulnerable log files.
Cisco has confirmed the vulnerability and released software updates.
To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requirement reduces the likelihood of a successful exploit.
Cisco indicates through the CVSS score that functional
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-08-20
Published