Description
Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 improperly checks for a user account's read-only attribute, which allows remote authenticated users to execute arbitrary OS commands via crafted HTTP requests, as demonstrated by read or write operations on the Unified Communications lookup page, aka Bug ID CSCuv12552.
Published: 2015-08-20
Score: 4.0 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2015-4351 Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 improperly checks for a user account's read-only attribute, which allows remote authenticated users to execute arbitrary OS commands via crafted HTTP requests, as demonstrated by read or write operations on the Unified Communications lookup page, aka Bug ID CSCuv12552.
History

No history.

Subscriptions

Cisco Telepresence Video Communication Server Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-08-06T06:11:12.925Z

Reserved: 2015-06-04T00:00:00.000Z

Link: CVE-2015-4328

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2015-08-20T00:59:06.060

Modified: 2026-05-06T22:30:45.220

Link: CVE-2015-4328

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses