cbcvebase.
CVE-2015-6261
published 2015-08-26

CVE-2015-6261: Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows remote authenticated users to bypass intended access restrictions and read…

PriorityP421medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
1.55%
72.1th percentile
Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows remote authenticated users to bypass intended access restrictions and read configuration files by leveraging the Mobile and Remote Access (MRA) role and establishing a TFTP session, aka Bug ID CSCuv78531.

Affected

3 ranges
VendorProductVersion rangeFixed in
ciscotelepresence_video_communication_server_software
gnulibidn>= 0 < 1.28-1ubuntu2.11.28-1ubuntu2.1
gnulibidn>= 0 < 1.32-3ubuntu1.11.32-3ubuntu1.1

CVSS provenance

nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv7.5HIGH
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.