Severity
6.5MEDIUM
EPSS
0.1%
top 71.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 7
Latest updateMay 13

Description

The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7 and Expressway X8.1 through X8.6 mishandles certificates, which allows remote attackers to bypass authentication via an arbitrary trusted certificate, aka Bug ID CSCuz64601.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 3.9 | Impact: 2.5

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-5855-5x6f-x6w6: The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X82022-05-13
CVEList
CVE-2016-1444: The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X82016-07-07

📋Vendor Advisories

1
Cisco
Cisco Video Communication Server and Expressway Trusted Certificate Authentication Bypass Vulnerability2016-07-06
CVE-2016-1444 (MEDIUM CVSS 6.5) | The Mobile and Remote Access (MRA) | cvebase.io