Lucene search

K
cve[email protected]CVE-2015-6413
HistoryDec 13, 2015 - 3:59 a.m.

CVE-2015-6413

2015-12-1303:59:07
CWE-264
web.nvd.nist.gov
23
cisco
vcs expressway
x8.6
authenticated users
read-only restrictions
file upload
security vulnerability
cve-2015-6413
nvd

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

6.5 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

41.4%

Cisco TelePresence Video Communication Server (VCS) Expressway X8.6 allows remote authenticated users to bypass intended read-only restrictions and upload Tandberg Linux Package (TLP) files by visiting an administrative page, aka Bug ID CSCuw55651.

Affected configurations

NVD
Node
ciscotelepresence_video_communication_server_softwareMatchx8.6expressway

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

6.5 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

41.4%