Cisco TelePresence VCS Expressway information leakage (CVE-2015-4320)
Cisco TelePresence VCS Expressway information leakage (CVE-2015-4320)
Release date:
Updated on:
Affected Systems:
Cisco TelePresence Video Communication Server X8.5.2
Description:
CVE (CAN) ID: CVE-2015-4320
Cisco TelePresence is a Cisco TelePresence solution.
In Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2, the Configuration Log File component has a security vulnerability that allows authenticated remote users to obtain sensitive information by reading Log files.
<* Source: Cisco
Link: http://tools.cisco.com/security/center/viewAlert.x? AlertId = 40441
*>
Suggestion:
Vendor patch:
Cisco
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://tools.cisco.com/security/center/viewAlert.x? AlertId = 40441
This article permanently updates the link address: