CVE-2015-6413
published 2015-12-13CVE-2015-6413: Cisco TelePresence Video Communication Server (VCS) Expressway X8.6 allows remote authenticated users to bypass intended read-only restrictions and upload…
PriorityP420medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
1.68%
74.3th percentile
Cisco TelePresence Video Communication Server (VCS) Expressway X8.6 allows remote authenticated users to bypass intended read-only restrictions and upload Tandberg Linux Package (TLP) files by visiting an administrative page, aka Bug ID CSCuw55651.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_video_communication_server_expressway_web_framework_code_unauthoriz | — | — |
| cisco | telepresence_video_communication_server_software | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco TelePresence Video Communication Server Expressway Web Framework Code Unauthorized Access Vulnerability
vendor_cisco·2015-12-09·CVSS 4.0
CVE-2015-6413 [MEDIUM] CWE-264 Cisco TelePresence Video Communication Server Expressway Web Framework Code Unauthorized Access Vulnerability
Cisco TelePresence Video Communication Server Expressway Web Framework Code Unauthorized Access Vulnerability
A vulnerability in the web framework code of Cisco TelePresence Video Communication Server (VCS) Expressway could allow an authenticated, remote attacker to install Tandberg Linux Packages (TLPs) without proper authorization.
The vulnerability is due to missing authorization checks on certain administrative pages. An attacker could exploit this vulnerability by using certain pages to upload TLP files as a read-only user. An exploit could allow the attacker to change the contents of VCS Expressway.
Cisco has not released software updates that address this vulnerability. There are no workarounds that mitigate this vulnerability.
This advisory is available at the following link:
Cisco
Cisco TelePresence Video Communication Server Expressway Web Framework Code Unauthorized Access Vulnerability
vendor_cisco
CVE-2015-6413 Cisco TelePresence Video Communication Server Expressway Web Framework Code Unauthorized Access Vulnerability
CVE-2015-6413: Cisco TelePresence Video Communication Server Expressway Web Framework Code Unauthorized Access Vulnerability
A vulnerability in the web framework code of Cisco TelePresence Video Communication Server (VCS) Expressway could allow an authenticated, remote attacker to install Tandberg Linux Packages (TLPs) without proper authorization. The vulnerability is due to missing authorization checks on certain administrative pages. An attacker could exploit this vulnerability by using certain pages to upload TLP files as a read-only user. An exploit could allow the attacker to change the contents of VCS Expressway. Cisco has not released software updates that address this vulnerability. There are no
CWE: CWE-264, CWE-264
Bug IDs: CSCuw55651
GHSA
GHSA-58fm-pmp5-q9g7: Cisco TelePresence Video Communication Server (VCS) Expressway X8
ghsa_unreviewed·2022-05-17
CVE-2015-6413 [MEDIUM] GHSA-58fm-pmp5-q9g7: Cisco TelePresence Video Communication Server (VCS) Expressway X8
Cisco TelePresence Video Communication Server (VCS) Expressway X8.6 allows remote authenticated users to bypass intended read-only restrictions and upload Tandberg Linux Package (TLP) files by visiting an administrative page, aka Bug ID CSCuw55651.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151209-tvchttp://www.securityfocus.com/bid/79088http://www.securitytracker.com/id/1034378http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151209-tvchttp://www.securityfocus.com/bid/79088http://www.securitytracker.com/id/1034378
2015-12-13
Published