First published: Sat Nov 21 2015(Updated: )
Cross-site request forgery (CSRF) vulnerability in Cisco TelePresence Video Communication Server (VCS) X8.5.1 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuv72412.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco TelePresence Video Communication Server Firmware | =x8.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6376 is considered to have a high severity level due to its potential for remote exploitation and user authentication hijacking.
To fix CVE-2015-6376, update the Cisco TelePresence Video Communication Server to the latest version that addresses this vulnerability.
CVE-2015-6376 specifically affects Cisco TelePresence Video Communication Server version X8.5.1.
CVE-2015-6376 is associated with a cross-site request forgery (CSRF) attack, allowing unauthorized actions on behalf of users.
Remote attackers with knowledge of the vulnerability can exploit CVE-2015-6376 to hijack the authentication of arbitrary users.