CVE-2016-1468
high
CVSS v3
8.8
CVSS v2
6.5
VIR risk
8.8
Description
The administrative web interface in Cisco TelePresence Video Communication Server Expressway X8.5.2 allows remote authenticated users to execute arbitrary commands via crafted fields, aka Bug ID CSCuv12531.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@cisco.com — http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160803-vcse
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| cisco | telepresence_video_communication_server | x8.5.2 | |
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160803-vcse
- http://www.securityfocus.com/bid/92274
- http://www.securitytracker.com/id/1036529
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160803-vcse
- http://www.securityfocus.com/bid/92274
- http://www.securitytracker.com/id/1036529
CWEs
CWE-78
Verify integrity in audit chain (admin only). AS-IS.