CVE-2015-4328: Input Validation
Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 improperly checks for a user account's read-only attribute, which allows remote authenticated users to execute arbitrary OS commands via crafted HTTP requests, as demonstrated by read or write operations on the Unified Communications lookup page, aka Bug ID CSCuv12552.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4328?
CVE-2015-4328 has been rated as critical due to its potential for allowing unauthorized command execution.
How do I fix CVE-2015-4328?
To remediate CVE-2015-4328, upgrade to a fixed version of the Cisco TelePresence Video Communication Server software.
Who is affected by CVE-2015-4328?
CVE-2015-4328 affects Cisco TelePresence Video Communication Server Software version x8.5.2.
What type of vulnerability is CVE-2015-4328?
CVE-2015-4328 is a command injection vulnerability that allows remote authenticated users to execute arbitrary OS commands.
What exploitation techniques are used with CVE-2015-4328?
Exploitation of CVE-2015-4328 can occur through crafted HTTP requests sent by an authenticated user.