CVE-2015-6414
published 2015-12-13CVE-2015-6414: Cisco TelePresence Video Communication Server (VCS) X8.6 uses the same encryption key across different customers' installations, which makes it easier for…
PriorityP47low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.23%
14.0th percentile
Cisco TelePresence Video Communication Server (VCS) X8.6 uses the same encryption key across different customers' installations, which makes it easier for local users to defeat cryptographic protection mechanisms by leveraging knowledge of a key from another installation, aka Bug ID CSCuw64516.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_video_communication_server | — | — |
| cisco | telepresence_video_communication_server_software | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-876p-j7c4-v654: Cisco TelePresence Video Communication Server (VCS) X8
ghsa_unreviewed·2022-05-17
CVE-2015-6414 [LOW] CWE-200 GHSA-876p-j7c4-v654: Cisco TelePresence Video Communication Server (VCS) X8
Cisco TelePresence Video Communication Server (VCS) X8.6 uses the same encryption key across different customers' installations, which makes it easier for local users to defeat cryptographic protection mechanisms by leveraging knowledge of a key from another installation, aka Bug ID CSCuw64516.
Cisco
Cisco TelePresence Video Communication Server Information Disclosure Vulnerability
vendor_cisco·2015-12-10·CVSS 2.1
CVE-2015-6414 [LOW] CWE-200 Cisco TelePresence Video Communication Server Information Disclosure Vulnerability
Cisco TelePresence Video Communication Server Information Disclosure Vulnerability
A vulnerability in the key management of Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, local attacker to read sensitive data.
The vulnerability is due to an encryption key that is shared across all the installations of VCS. An attacker could exploit this vulnerability by determining the key and decrypting certain data sets. An exploit could allow the attacker to read and disclose certain sensitive data.
Cisco has not released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa
Cisco
Cisco TelePresence Video Communication Server Information Disclosure Vulnerability
vendor_cisco
CVE-2015-6414 Cisco TelePresence Video Communication Server Information Disclosure Vulnerability
CVE-2015-6414: Cisco TelePresence Video Communication Server Information Disclosure Vulnerability
A vulnerability in the key management of Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, local attacker to read sensitive data. The vulnerability is due to an encryption key that is shared across all the installations of VCS. An attacker could exploit this vulnerability by determining the key and decrypting certain data sets. An exploit could allow the attacker to read and disclose certain sensitive data. Cisco has not released software updates that address this vulnerability. There are no
CWE: CWE-200, CWE-200
Bug IDs: CSCuw64516
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151210-tvcshttp://www.securityfocus.com/bid/79065http://www.securitytracker.com/id/1034429http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151210-tvcshttp://www.securityfocus.com/bid/79065http://www.securitytracker.com/id/1034429
2015-12-13
Published