First published: Mon Oct 12 2015(Updated: )
Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.1 and X8.5.2 allows local users to write to arbitrary files via an unspecified symlink attack, aka Bug ID CSCuv11969.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco TelePresence Video Communication Server Firmware | =x8.5.1 | |
Cisco TelePresence Video Communication Server Firmware | =x8.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6318 is considered to have a high severity due to its potential to allow local users to write to arbitrary files.
To mitigate CVE-2015-6318, upgrade Cisco TelePresence Video Communication Server to version X8.5.3 or later.
CVE-2015-6318 affects Cisco TelePresence Video Communication Server versions X8.5.1 and X8.5.2.
CVE-2015-6318 is primarily an issue that affects local users, not remote exploitation.
There are no official workarounds for CVE-2015-6318; upgrading to a patched version is recommended for protection.