CVE-2018-15430
published 2018-10-05CVE-2018-15430: A vulnerability in the administrative web interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an…
PriorityP346high7.2CVSS 3.0
AVNACLPRHUINSUCHIHAH
EPSS
2.87%
85.2th percentile
A vulnerability in the administrative web interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with user-level privileges on the underlying operating system. The vulnerability is due to insufficient validation of the content of upgrade packages. An attacker could exploit this vulnerability by uploading a malicious archive to the Upgrade page of the administrative web interface. A successful exploit could allow the attacker to execute code with user-level privileges on the underlying operating system.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_telepresence_video_communication_server | — | — |
| cisco | expressway_series_and_cisco_telepresence_video_communication_server | — | — |
| cisco | telepresence_video_communication_server | — | — |
| cisco | telepresence_video_communication_server | — | — |
| cisco | telepresence_video_communication_server | — | — |
CVSS provenance
nvdv3.07.2HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Expressway Series and Cisco TelePresence Video Communication Server Remote Code Execution Vulnerability
vendor_cisco·2018-10-03·CVSS 4.7
CVE-2018-15430 [MEDIUM] CWE-20 Cisco Expressway Series and Cisco TelePresence Video Communication Server Remote Code Execution Vulnerability
Cisco Expressway Series and Cisco TelePresence Video Communication Server Remote Code Execution Vulnerability
A vulnerability in the administrative web interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with user-level privileges on the underlying operating system.
The vulnerability is due to insufficient validation of the content of upgrade packages. An attacker could exploit this vulnerability by uploading a malicious archive to the Upgrade page of the administrative web interface. A successful exploit could allow the attacker to execute code with user-level privileges on the underlying operating system.
There are no workarounds that address this vulnerability.
This advisory is avail
Cisco
Cisco Expressway Series and Cisco TelePresence Video Communication Server Remote Code Execution Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-15430 Cisco Expressway Series and Cisco TelePresence Video Communication Server Remote Code Execution Vulnerability
CVE-2018-15430: Cisco Expressway Series and Cisco TelePresence Video Communication Server Remote Code Execution Vulnerability
A vulnerability in the administrative web interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with user-level privileges on the underlying operating system. The vulnerability is due to insufficient validation of the content of upgrade packages. An attacker could exploit this vulnerability by uploading a malicious archive to the Upgrade page of the administrative web interface. A successful exploit could allow the attacker to execute code with user-level privileges on the underlying operating system. There are no
CVSS: 3.0
CWE: CWE-20, CWE-20
Bug IDs: CSCvi50935
GHSA
GHSA-gv37-765c-v9fx: A vulnerability in the administrative web interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an
ghsa_unreviewed·2022-05-13
CVE-2018-15430 [HIGH] CWE-20 GHSA-gv37-765c-v9fx: A vulnerability in the administrative web interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an
A vulnerability in the administrative web interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with user-level privileges on the underlying operating system. The vulnerability is due to insufficient validation of the content of upgrade packages. An attacker could exploit this vulnerability by uploading a malicious archive to the Upgrade page of the administrative web interface. A successful exploit could allow the attacker to execute code with user-level privileges on the underlying operating system.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-10-05
Published