CVE-2015-6414: Infoleak
Cisco TelePresence Video Communication Server (VCS) X8.6 uses the same encryption key across different customers' installations, which makes it easier for local users to defeat cryptographic protection mechanisms by leveraging knowledge of a key from another installation, aka Bug ID CSCuw64516.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6414?
CVE-2015-6414 has a CVSS score that indicates it has a high severity due to the potential for cryptographic key compromise.
How do I fix CVE-2015-6414?
To fix CVE-2015-6414, upgrade to a version of Cisco TelePresence Video Communication Server that uses unique encryption keys for each installation.
What are the risks associated with CVE-2015-6414?
The risks associated with CVE-2015-6414 include unauthorized access to encrypted communications due to key reuse across installations.
Which Cisco products are affected by CVE-2015-6414?
CVE-2015-6414 specifically affects Cisco TelePresence Video Communication Server software version X8.6.
Is CVE-2015-6414 exploitable remotely?
CVE-2015-6414 is not considered remotely exploitable but can be exploited locally by users who know the shared key.