CVE-2015-4329: Input Validation
The administrator web interface in Cisco TelePresence Video Communication Server (VCS) X8.5.2 allows remote authenticated users to execute arbitrary OS commands via crafted HTTP requests, aka Bug ID CSCuv11796.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4329?
CVE-2015-4329 has a CVSS score that indicates it is a medium to high severity vulnerability.
How do I fix CVE-2015-4329?
To fix CVE-2015-4329, upgrade your Cisco TelePresence Video Communication Server to a version that is not affected by this vulnerability.
Who is affected by CVE-2015-4329?
CVE-2015-4329 affects remote authenticated users of Cisco TelePresence Video Communication Server running version X8.5.2.
What kind of impact does CVE-2015-4329 have?
CVE-2015-4329 allows remote authenticated users to execute arbitrary OS commands, potentially compromising the system.
Is there a workaround for CVE-2015-4329?
Currently, there are no documented workarounds for CVE-2015-4329, and it is recommended to apply updates.