CVE-2016-1316: Infoleak
Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7, as used in conjunction with Jabber Guest, allows remote attackers to obtain sensitive call-statistics information via a direct request to an unspecified URL, aka Bug ID CSCux73362.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1316?
CVE-2016-1316 has a medium severity level, as it allows remote attackers to access sensitive call-statistics information.
How do I fix CVE-2016-1316?
To fix CVE-2016-1316, upgrade the Cisco TelePresence Video Communication Server to a version higher than X8.7.
What versions of Cisco TelePresence Video Communication Server are affected by CVE-2016-1316?
Versions X8.1 through X8.7 of Cisco TelePresence Video Communication Server are affected by CVE-2016-1316.
What kind of information can be accessed due to CVE-2016-1316?
CVE-2016-1316 allows attackers to access sensitive call-statistics information through direct requests to an unspecified URL.
Is there a workaround for CVE-2016-1316?
Currently, there is no documented workaround for CVE-2016-1316; upgrading to a fixed version is recommended.