CVE-2015-6413: Medium severity cisco telepresence video communication server firmware vulnerability
Published Dec 13, 2015
·Updated
Cisco TelePresence Video Communication Server (VCS) Expressway X8.6 allows remote authenticated users to bypass intended read-only restrictions and upload Tandberg Linux Package (TLP) files by visiting an administrative page, aka Bug ID CSCuw55651.
Affected Software
1 affected component
Cisco Telepresence Video Communication Server Software=x8.6
Event History
Dec 13, 2015
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6413?
CVE-2015-6413 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2015-6413?
To mitigate CVE-2015-6413, update the Cisco TelePresence Video Communication Server to a patched version beyond X8.6.
3
What type of access does CVE-2015-6413 allow?
CVE-2015-6413 allows remote authenticated users to bypass read-only restrictions on the device.
4
What actions are affected by CVE-2015-6413?
CVE-2015-6413 enables the upload of Tandberg Linux Package files through an administrative page.
5
Which Cisco product is impacted by CVE-2015-6413?
CVE-2015-6413 affects the Cisco TelePresence Video Communication Server software version X8.6.