Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.107025
Category:CISCO
Title:Cisco Video Communication Server Trusted Certificate Authentication Bypass Vulnerability (cisco-sa-20160706-vcs)
Summary:A vulnerability in certificate management and validation for; the Mobile and Remote Access (MRA) feature for Cisco TelePresence Video Communication Server; (VCS) could allow an unauthenticated, remote attacker to bypass authentication and access; internal HTTP system resources.
Description:Summary:
A vulnerability in certificate management and validation for
the Mobile and Remote Access (MRA) feature for Cisco TelePresence Video Communication Server
(VCS) could allow an unauthenticated, remote attacker to bypass authentication and access
internal HTTP system resources.

Vulnerability Insight:
The vulnerability is due to lack of proper input validation of
a trusted certificate. An attacker could exploit this vulnerability by connecting to the targeted
device with a trusted certificate.

Vulnerability Impact:
An exploit could allow the attacker to bypass authentication and
access internal HTTP system resources.

Affected Software/OS:
Cisco TelePresence Video Communication Server (VCS) X8.1
through X8.7.

Solution:
See the referenced vendor advisory for a solution.

CVSS Score:
5.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-1444
BugTraq ID: 91669
http://www.securityfocus.com/bid/91669
Cisco Security Advisory: 20160706 Cisco Video Communication Server and Expressway Trusted Certificate Authentication Bypass Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160706-vcs
http://www.securitytracker.com/id/1036237
CopyrightCopyright (C) 2016 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.