Information Disclosure in Cisco TelePresence IX5000 by Cisco
CVE-2015-6276

Currently unrated

Key Information:

Vendor
Cisco
Vendor
CVE Published:
5 September 2015

Summary

The Cisco TelePresence IX5000 version 8.0.3 contains a vulnerability that exposes a private key associated with an X.509 certificate due to improper access control. This security flaw enables remote attackers to obtain cleartext versions of HTTPS traffic or potentially spoof devices by sending direct requests to the directory where the certificate is stored. Proper measures should be taken to secure the private key against unauthorized access to mitigate this risk.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.