CVE-2015-6261: Infoleak
Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows remote authenticated users to bypass intended access restrictions and read configuration files by leveraging the Mobile and Remote Access (MRA) role and establishing a TFTP session, aka Bug ID CSCuv78531.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6261?
CVE-2015-6261 is classified as a high-severity vulnerability due to its potential for unauthorized access to configuration files.
How do I fix CVE-2015-6261?
To mitigate CVE-2015-6261, upgrade to a patched version of the Cisco TelePresence Video Communication Server software that addresses this vulnerability.
Who is affected by CVE-2015-6261?
Organizations using Cisco TelePresence Video Communication Server software version X8.5.2 are at risk of being affected by CVE-2015-6261.
What types of access does CVE-2015-6261 allow?
CVE-2015-6261 allows remote authenticated users to bypass access restrictions and read sensitive configuration files.
What is the cause of CVE-2015-6261?
The vulnerability in CVE-2015-6261 is caused by the Mobile and Remote Access role permitting unauthorized access during TFTP sessions.