CVE-2016-1444
Severity
6.5MEDIUM
EPSS
0.1%
top 71.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 7
Latest updateMay 13
Description
The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7 and Expressway X8.1 through X8.6 mishandles certificates, which allows remote attackers to bypass authentication via an arbitrary trusted certificate, aka Bug ID CSCuz64601.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 3.9 | Impact: 2.5
Affected Packages2 packages
🔴Vulnerability Details
2📋Vendor Advisories
1Cisco▶
Cisco Video Communication Server and Expressway Trusted Certificate Authentication Bypass Vulnerability↗2016-07-06