CVE-2015-6261
published 2015-08-26CVE-2015-6261: Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows remote authenticated users to bypass intended access restrictions and read…
PriorityP421medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
1.55%
72.1th percentile
Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows remote authenticated users to bypass intended access restrictions and read configuration files by leveraging the Mobile and Remote Access (MRA) role and establishing a TFTP session, aka Bug ID CSCuv78531.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_video_communication_server_software | — | — |
| gnu | libidn | >= 0 < 1.28-1ubuntu2.1 | 1.28-1ubuntu2.1 |
| gnu | libidn | >= 0 < 1.32-3ubuntu1.1 | 1.32-3ubuntu1.1 |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv7.5HIGH
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco TelePresence Video Communication Server Expressway TFTP Information Disclosure Vulnerability
vendor_cisco·2015-08-25·CVSS 4.0
CVE-2015-6261 [MEDIUM] CWE-200 Cisco TelePresence Video Communication Server Expressway TFTP Information Disclosure Vulnerability
Cisco TelePresence Video Communication Server Expressway TFTP Information Disclosure Vulnerability
A vulnerability in TFTP in Cisco TelePresence Video Communication Server (VCS) Expressway could allow an authenticated, remote attacker to obtain unauthorized access to configuration files from the device by using TFTP.
The vulnerability is due to lack of TFTP authentication and control for the privilege level needed to obtain a configuration file from the device. An attacker with the Mobile and Remote Access (MRA) role could exploit the vulnerability by using TFTP to obtain unauthorized access to configuration files. An exploit could allow the attacker to view sensitive information in the configuration file.
Cisco has confirmed the vulnerability; however, software updates are not availabl
GHSA
GHSA-pc34-r93m-6qjp: Cisco TelePresence Video Communication Server (VCS) Expressway X8
ghsa_unreviewed·2022-05-17
CVE-2015-6261 [MEDIUM] CWE-200 GHSA-pc34-r93m-6qjp: Cisco TelePresence Video Communication Server (VCS) Expressway X8
Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows remote authenticated users to bypass intended access restrictions and read configuration files by leveraging the Mobile and Remote Access (MRA) role and establishing a TFTP session, aka Bug ID CSCuv78531.
OSV
libidn vulnerabilities
osv·2016-08-24·CVSS 7.5
CVE-2015-2059 libidn vulnerabilities
libidn vulnerabilities
Thijs Alkemade, Gustavo Grieco, Daniel Stenberg, and Nikos
Mavrogiannopoulos discovered that Libidn incorrectly handled invalid UTF-8
characters. A remote attacker could use this issue to cause Libidn to
crash, resulting in a denial of service, or possibly disclose sensitive
memory. This issue only applied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.
(CVE-2015-2059)
Hanno Böck discovered that Libidn incorrectly handled certain input. A
remote attacker could possibly use this issue to cause Libidn to crash,
resulting in a denial of service. (CVE-2015-8948, CVE-2016-6262,
CVE-2016-6261, CVE-2016-6263)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-08-26
Published