Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.105334
Category:CISCO
Title:Cisco TelePresence Video Communication Server Expressway Information Disclosure Vulnerability (Cisco-SA-20150812-CVE-2015-4314)
Summary:A vulnerability in the System Snapshot of Cisco TelePresence; Video Communication Server (VCS) Expressway could allow an authenticated, remote attacker to view; sensitive data.
Description:Summary:
A vulnerability in the System Snapshot of Cisco TelePresence
Video Communication Server (VCS) Expressway could allow an authenticated, remote attacker to view
sensitive data.

Vulnerability Insight:
The vulnerability is due to insufficient protection of data at
rest. An attacker could exploit this vulnerability by downloading the snapshot file and viewing
the password hashes in it.

Vulnerability Impact:
An exploit could allow the attacker to crack the password hashes
and use the credentials to launch further attacks.

Affected Software/OS:
Cisco TelePresence Video Communication Server Expressway
version X8.5.1.

Solution:
Update to version X8.7 or later.

CVSS Score:
4.0

CVSS Vector:
AV:N/AC:L/Au:S/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2015-4314
Cisco Security Advisory: 20150812 Cisco TelePresence Video Communication Server Expressway Information Disclosure Vulnerability
http://tools.cisco.com/security/center/viewAlert.x?alertId=40439
http://www.securitytracker.com/id/1033266
CopyrightCopyright (C) 2015 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.