First published: Sun Dec 13 2015(Updated: )
Cisco TelePresence Video Communication Server (VCS) Expressway X8.6 allows remote authenticated users to bypass intended read-only restrictions and upload Tandberg Linux Package (TLP) files by visiting an administrative page, aka Bug ID CSCuw55651.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco TelePresence Video Communication Server Firmware | =x8.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6413 is classified as a moderate severity vulnerability.
To mitigate CVE-2015-6413, update the Cisco TelePresence Video Communication Server to a patched version beyond X8.6.
CVE-2015-6413 allows remote authenticated users to bypass read-only restrictions on the device.
CVE-2015-6413 enables the upload of Tandberg Linux Package files through an administrative page.
CVE-2015-6413 affects the Cisco TelePresence Video Communication Server software version X8.6.