CVE-2015-4319: Medium severity cisco telepresence video communication server firmware vulnerability
The password-change feature in the administrative web interface in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.1 improperly performs authorization, which allows remote authenticated users to reset arbitrary active-user passwords via unspecified vectors, aka Bug ID CSCuv12338.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4319?
CVE-2015-4319 has a medium severity rating due to its potential for unauthorized password resets.
How do I fix CVE-2015-4319?
To fix CVE-2015-4319, upgrade your Cisco TelePresence Video Communication Server to a version that includes the patch addressing this vulnerability.
What are the consequences of CVE-2015-4319?
Exploitation of CVE-2015-4319 allows authenticated users to reset passwords of any active user, leading to potential unauthorized access.
Is Cisco TelePresence Video Communication Server x8.5.1 the only affected version for CVE-2015-4319?
Yes, Cisco TelePresence Video Communication Server version x8.5.1 is specifically identified as affected by CVE-2015-4319.
Who can exploit CVE-2015-4319?
CVE-2015-4319 can be exploited by remote authenticated users who gain access to the administrative web interface.