Cisco TelePresence VCS Expressway information leakage (CVE-2015-4314)
Cisco TelePresence VCS Expressway information leakage (CVE-2015-4314)
Release date:
Updated on:
Affected Systems:
Cisco TelePresence Video Communication Server X8.5.1
Description:
CVE (CAN) ID: CVE-2015-4314
Cisco TelePresence is a Cisco TelePresence solution.
In Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.1, the System Snapshot function has a security vulnerability that allows authenticated remote users to obtain the password hash information by reading the Snapshot file.
<* Source: Cisco
Link: http://tools.cisco.com/security/center/viewAlert.x? AlertId = 40439
*>
Suggestion:
Vendor patch:
Cisco
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://tools.cisco.com/security/center/viewAlert.x? AlertId = 40439
This article permanently updates the link address: