Authentication Bypass in Cisco TelePresence Video Communication Server and Expressway
CVE-2016-1444

6.5MEDIUM

Summary

The Mobile and Remote Access component in Cisco TelePresence Video Communication Server (VCS) and Expressway mishandles certificate validation. This flaw enables attackers to bypass authentication mechanisms by exploiting arbitrary trusted certificates, potentially leading to unauthorized access to the system. Versions impacted include VCS X8.1 through X8.7 and Expressway X8.1 through X8.6, highlighting the need for immediate updates to safeguard against this vulnerability.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.