CVE-2015-4316
The Mobile and Remote Access (MRA) endpoint-validation feature in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 improperly validates the phone line used for registration, which allows remote authenticated users to conduct…
Does this matter?
Lower severity and a low EPSS score (1.89%). Track it; it rarely justifies an emergency change on its own.
Description
The Mobile and Remote Access (MRA) endpoint-validation feature in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 improperly validates the phone line used for registration, which allows remote authenticated users to conduct impersonation attacks via a crafted registration, aka Bug ID CSCuv40396.
- CVSS 2.0
- 5.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:P
- EPSS
- 1.89% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- cisco/telepresence video communication server software
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/viewAlert.x?alertId=40445Vendor Advisory
- http://www.securityfocus.com/bid/76353
- http://www.securitytracker.com/id/1033282
- http://tools.cisco.com/security/center/viewAlert.x?alertId=40445Vendor Advisory
- http://www.securityfocus.com/bid/76353
- http://www.securitytracker.com/id/1033282
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.