CVE-2016-1444: Input Validation
The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7 and Expressway X8.1 through X8.6 mishandles certificates, which allows remote attackers to bypass authentication via an arbitrary trusted certificate, aka Bug ID CSCuz64601.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1444?
CVE-2016-1444 has been assigned a high severity rating due to its potential to allow unauthorized access to the system.
How do I fix CVE-2016-1444?
To fix CVE-2016-1444, upgrade the affected Cisco TelePresence Video Communication Server or Expressway software to a version that resolves this vulnerability.
Which versions are affected by CVE-2016-1444?
CVE-2016-1444 affects Cisco TelePresence Video Communication Server versions X8.1 through X8.7 and Expressway versions X8.1 through X8.6.
What is the impact of exploiting CVE-2016-1444?
Exploiting CVE-2016-1444 allows remote attackers to bypass authentication using an arbitrary trusted certificate.
Are there any workarounds for CVE-2016-1444?
There are no recommended workarounds for CVE-2016-1444; the best course of action is to apply the appropriate software updates.