CVE-2018-15430: Cisco Expressway Series and Cisco TelePresence Video Communication Server Remote Code Execution Vulnerability
A vulnerability in the administrative web interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with user-level privileges on the underlying operating system. The vulnerability is due to insufficient validation of the content of upgrade packages. An attacker could exploit this vulnerability by uploading a malicious archive to the Upgrade page of the administrative web interface. A successful exploit could allow the attacker to execute code with user-level privileges on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15430?
CVE-2018-15430 is a vulnerability in the administrative web interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) that could allow an authenticated, remote attacker to execute code with user-level privileges on the underlying operating system.
How severe is CVE-2018-15430?
CVE-2018-15430 has a severity rating of 7.2 out of 10, which is considered high.
Which software versions are affected by CVE-2018-15430?
CVE-2018-15430 affects Cisco TelePresence Video Communication Server versions x7.2.4, x8.9.2, and x8.10.4.
How can an attacker exploit CVE-2018-15430?
An attacker can exploit CVE-2018-15430 by accessing the administrative web interface and executing code with user-level privileges on the underlying operating system.
Are there any fixes or patches available for CVE-2018-15430?
Yes, Cisco has released security advisories recommending updates and patches to address CVE-2018-15430. Please refer to the official Cisco Security Advisory for more information.