CVE-2018-15430
published 2018-10-05CVE-2018-15430: A vulnerability in the administrative web interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an…
high7.2CVSS 3.0
AVNACLPRHUINSUCHIHAH
A vulnerability in the administrative web interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with user-level privileges on the underlying operating system. The vulnerability is due to insufficient validation of the content of upgrade packages. An attacker could exploit this vulnerability by uploading a malicious archive to the Upgrade page of the administrative web interface. A successful exploit could allow the attacker to execute code with user-level privileges on the underlying operating system.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_telepresence_video_communication_server | — | — |
| cisco | expressway_series_and_cisco_telepresence_video_communication_server | — | — |
| cisco | telepresence_video_communication_server | — | — |
| cisco | telepresence_video_communication_server | — | — |
| cisco | telepresence_video_communication_server | — | — |