First published: Thu Aug 20 2015(Updated: )
The Configuration Log File component in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows remote authenticated users to obtain sensitive information by reading a log file, aka Bug ID CSCuv12340.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco TelePresence Video Communication Server Firmware | =x8.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4320 is classified as a medium severity vulnerability that allows remote authenticated users to access sensitive information.
To fix CVE-2015-4320, upgrade the Cisco TelePresence Video Communication Server Software to the latest version that addresses this issue.
CVE-2015-4320 affects users of Cisco TelePresence Video Communication Server Software version x8.5.2.
CVE-2015-4320 is an information disclosure vulnerability that allows unauthorized access to configuration log files.
Yes, CVE-2015-4320 can be exploited by remote authenticated users who can read the log files.