CVE-2016-1444
published 2016-07-07CVE-2016-1444: The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7 and Expressway X8.1 through X8.6…
PriorityP343medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
1.20%
64.6th percentile
The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7 and Expressway X8.1 through X8.6 mishandles certificates, which allows remote attackers to bypass authentication via an arbitrary trusted certificate, aka Bug ID CSCuz64601.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_video_communication_server | — | — |
| cisco | telepresence_video_communication_server | — | — |
| cisco | telepresence_video_communication_server | — | — |
| cisco | telepresence_video_communication_server | — | — |
| cisco | telepresence_video_communication_server | — | — |
| cisco | telepresence_video_communication_server | — | — |
| cisco | telepresence_video_communication_server | — | — |
| cisco | telepresence_video_communication_server | — | — |
| cisco | telepresence_video_communication_server | — | — |
| cisco | telepresence_video_communication_server | — | — |
| cisco | telepresence_video_communication_server | — | — |
| cisco | telepresence_video_communication_server | — | — |
| cisco | telepresence_video_communication_server | — | — |
| cisco | telepresence_video_communication_server | — | — |
| cisco | telepresence_video_communication_server_software | — | — |
| cisco | telepresence_video_communication_server_software | — | — |
| cisco | telepresence_video_communication_server_software | — | — |
| cisco | telepresence_video_communication_server_software | — | — |
| cisco | video_communication_server_and_expressway_trusted | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_cisco5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5855-5x6f-x6w6: The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X8
ghsa_unreviewed·2022-05-13
CVE-2016-1444 [MEDIUM] CWE-20 GHSA-5855-5x6f-x6w6: The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X8
The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7 and Expressway X8.1 through X8.6 mishandles certificates, which allows remote attackers to bypass authentication via an arbitrary trusted certificate, aka Bug ID CSCuz64601.
Cisco
Cisco Video Communication Server and Expressway Trusted Certificate Authentication Bypass Vulnerability
vendor_cisco·2016-07-06·CVSS 5.8
CVE-2016-1444 [MEDIUM] CWE-287 Cisco Video Communication Server and Expressway Trusted Certificate Authentication Bypass Vulnerability
Cisco Video Communication Server and Expressway Trusted Certificate Authentication Bypass Vulnerability
A vulnerability in certificate management and validation for the Mobile and Remote Access (MRA) feature for Cisco Expressway Series and TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to bypass authentication and access internal HTTP system resources.
The vulnerability is due to lack of proper input validation of a trusted certificate. An attacker could exploit this vulnerability by connecting to the targeted device with a trusted certificate. An exploit could allow the attacker to bypass authentication and access internal HTTP system resources.
Cisco has released software updates that address this vulnerability. Workarounds that address t
Cisco
Cisco Video Communication Server and Expressway Trusted Certificate Authentication Bypass Vulnerability
vendor_cisco
CVE-2016-1444 Cisco Video Communication Server and Expressway Trusted Certificate Authentication Bypass Vulnerability
CVE-2016-1444: Cisco Video Communication Server and Expressway Trusted Certificate Authentication Bypass Vulnerability
A vulnerability in certificate management and validation for the Mobile and Remote Access (MRA) feature for Cisco Expressway Series and TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to bypass authentication and access internal HTTP system resources. The vulnerability is due to lack of proper input validation of a trusted certificate. An attacker could exploit this vulnerability by connecting to the targeted device with a trusted certificate. An exploit could allow the attacker to bypass authentication and access internal HTTP system resources. Cisco has released software updates that address this vulnerability.
CWE: CWE-287,
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160706-vcshttp://www.securityfocus.com/bid/91669http://www.securitytracker.com/id/1036237http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160706-vcshttp://www.securityfocus.com/bid/91669http://www.securitytracker.com/id/1036237
2016-07-07
Published