CVE-2015-6318: Input Validation
Published Oct 12, 2015
·Updated
Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.1 and X8.5.2 allows local users to write to arbitrary files via an unspecified symlink attack, aka Bug ID CSCuv11969.
Affected Software
2 affected components
Cisco Telepresence Video Communication Server Software=x8.5.1
Cisco Telepresence Video Communication Server Software=x8.5.2
Event History
Oct 12, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6318?
CVE-2015-6318 is considered to have a high severity due to its potential to allow local users to write to arbitrary files.
2
How do I fix CVE-2015-6318?
To mitigate CVE-2015-6318, upgrade Cisco TelePresence Video Communication Server to version X8.5.3 or later.
3
What systems are affected by CVE-2015-6318?
CVE-2015-6318 affects Cisco TelePresence Video Communication Server versions X8.5.1 and X8.5.2.
4
Can CVE-2015-6318 be exploited remotely?
CVE-2015-6318 is primarily an issue that affects local users, not remote exploitation.
5
Is there a workaround for CVE-2015-6318?
There are no official workarounds for CVE-2015-6318; upgrading to a patched version is recommended for protection.