Authentication Bypass in Cisco TelePresence Video Communication Server and Expressway
CVE-2016-1444
6.5MEDIUM
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 7 July 2016
Summary
The Mobile and Remote Access component in Cisco TelePresence Video Communication Server (VCS) and Expressway mishandles certificate validation. This flaw enables attackers to bypass authentication mechanisms by exploiting arbitrary trusted certificates, potentially leading to unauthorized access to the system. Versions impacted include VCS X8.1 through X8.7 and Expressway X8.1 through X8.6, highlighting the need for immediate updates to safeguard against this vulnerability.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved