cbcvebase.
CVE-2018-15430
published 2018-10-05

CVE-2018-15430: A vulnerability in the administrative web interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an…

high7.2CVSS 3.0
AVNACLPRHUINSUCHIHAH
A vulnerability in the administrative web interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with user-level privileges on the underlying operating system. The vulnerability is due to insufficient validation of the content of upgrade packages. An attacker could exploit this vulnerability by uploading a malicious archive to the Upgrade page of the administrative web interface. A successful exploit could allow the attacker to execute code with user-level privileges on the underlying operating system.

Affected

5 ranges
VendorProductVersion rangeFixed in
ciscocisco_telepresence_video_communication_server
ciscoexpressway_series_and_cisco_telepresence_video_communication_server
ciscotelepresence_video_communication_server
ciscotelepresence_video_communication_server
ciscotelepresence_video_communication_server