CVE-2015-6318
published 2015-10-12CVE-2015-6318: Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.1 and X8.5.2 allows local users to write to arbitrary files via an unspecified symlink…
PriorityP424medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.36%
27.7th percentile
Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.1 and X8.5.2 allows local users to write to arbitrary files via an unspecified symlink attack, aka Bug ID CSCuv11969.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_video_communication_server_expressway_file_modification | — | — |
| cisco | telepresence_video_communication_server_software | — | — |
| cisco | telepresence_video_communication_server_software | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_cisco4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco TelePresence Video Communication Server Expressway File Modification Vulnerability
vendor_cisco·2015-10-07·CVSS 4.4
CVE-2015-6318 [MEDIUM] CWE-20 Cisco TelePresence Video Communication Server Expressway File Modification Vulnerability
Cisco TelePresence Video Communication Server Expressway File Modification Vulnerability
A vulnerability in the symbolic link operation of the Cisco TelePresence Video Communication Server (VCS) Expressway could allow an authenticated, local attacker to perform a symbolic link attack on the affected system.
The vulnerability is due to insufficient protection of files. An attacker could exploit this vulnerability by creating a malicious symbolic link to a location not otherwise accessible to the attacker. An exploit could allow the attacker to insert unauthorized content in the linked-to file.
Cisco has released software updates that address these vulnerabilities. Workarounds that mitigate these vulnerabilities are not available.
This advisory is available at the following link: https:/
Cisco
Cisco TelePresence Video Communication Server Expressway File Modification Vulnerability
vendor_cisco
CVE-2015-6318 Cisco TelePresence Video Communication Server Expressway File Modification Vulnerability
CVE-2015-6318: Cisco TelePresence Video Communication Server Expressway File Modification Vulnerability
A vulnerability in the symbolic link operation of the Cisco TelePresence Video Communication Server (VCS) Expressway could allow an authenticated, local attacker to perform a symbolic link attack on the affected system. The vulnerability is due to insufficient protection of files. An attacker could exploit this vulnerability by creating a malicious symbolic link to a location not otherwise accessible to the attacker. An exploit could allow the attacker to insert unauthorized content in the linked-to file. Cisco has released software updates that address these vulnerabilities.
CWE: CWE-20, CWE-20
Bug IDs: CSCuv11969
GHSA
GHSA-c4f9-xqxp-hcrv: Cisco TelePresence Video Communication Server (VCS) Expressway X8
ghsa_unreviewed·2022-05-17
CVE-2015-6318 [MEDIUM] CWE-20 GHSA-c4f9-xqxp-hcrv: Cisco TelePresence Video Communication Server (VCS) Expressway X8
Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.1 and X8.5.2 allows local users to write to arbitrary files via an unspecified symlink attack, aka Bug ID CSCuv11969.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-10-12
Published