CVE-2016-1444
 
Severity Score
6.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7 and Expressway X8.1 through X8.6 mishandles certificates, which allows remote attackers to bypass authentication via an arbitrary trusted certificate, aka Bug ID CSCuz64601.
El componente Mobile and Remote Access (MRA) en Cisco TelePresence Video Communication Server (VCS) X8.1 hasta la versión X8.7 y Expressway X8.1 hasta la versión X8.6 no maneja correctamente los certificados, lo que permite a atacantes remotos eludir la autenticación a través de un certificado confiable manipulado, también conocido como Bug ID CSCuz64601.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2016-01-04 CVE Reserved
- 2016-07-07 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/91669 | Third Party Advisory | |
http://www.securitytracker.com/id/1036237 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160706-vcs | 2020-08-27 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Telepresence Video Communication Server Search vendor "Cisco" for product "Telepresence Video Communication Server" | x8.1 Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Telepresence Video Communication Server Search vendor "Cisco" for product "Telepresence Video Communication Server" | x8.1.1 Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.1.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Telepresence Video Communication Server Search vendor "Cisco" for product "Telepresence Video Communication Server" | x8.1.2 Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.1.2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Telepresence Video Communication Server Search vendor "Cisco" for product "Telepresence Video Communication Server" | x8.2 Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Telepresence Video Communication Server Search vendor "Cisco" for product "Telepresence Video Communication Server" | x8.2.1 Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.2.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Telepresence Video Communication Server Search vendor "Cisco" for product "Telepresence Video Communication Server" | x8.2.2 Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.2.2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Telepresence Video Communication Server Search vendor "Cisco" for product "Telepresence Video Communication Server" | x8.5 Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.5" | rc4 |
Affected
| ||||||
Cisco Search vendor "Cisco" | Telepresence Video Communication Server Search vendor "Cisco" for product "Telepresence Video Communication Server" | x8.5.0 Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.5.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Telepresence Video Communication Server Search vendor "Cisco" for product "Telepresence Video Communication Server" | x8.5.1 Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.5.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Telepresence Video Communication Server Search vendor "Cisco" for product "Telepresence Video Communication Server" | x8.5.2 Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.5.2" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Telepresence Video Communication Server Search vendor "Cisco" for product "Telepresence Video Communication Server" | x8.5.3 Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.5.3" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Telepresence Video Communication Server Search vendor "Cisco" for product "Telepresence Video Communication Server" | x8.6.0 Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.6.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Telepresence Video Communication Server Search vendor "Cisco" for product "Telepresence Video Communication Server" | x8.6.1 Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.6.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Telepresence Video Communication Server Search vendor "Cisco" for product "Telepresence Video Communication Server" | x8.7 Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.7" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Telepresence Video Communication Server Software Search vendor "Cisco" for product "Telepresence Video Communication Server Software" | x8.5.1 Search vendor "Cisco" for product "Telepresence Video Communication Server Software" and version "x8.5.1" | expressway |
Affected
| ||||||
Cisco Search vendor "Cisco" | Telepresence Video Communication Server Software Search vendor "Cisco" for product "Telepresence Video Communication Server Software" | x8.5.2 Search vendor "Cisco" for product "Telepresence Video Communication Server Software" and version "x8.5.2" | expressway |
Affected
| ||||||
Cisco Search vendor "Cisco" | Telepresence Video Communication Server Software Search vendor "Cisco" for product "Telepresence Video Communication Server Software" | x8.5.3 Search vendor "Cisco" for product "Telepresence Video Communication Server Software" and version "x8.5.3" | expressway |
Affected
| ||||||
Cisco Search vendor "Cisco" | Telepresence Video Communication Server Software Search vendor "Cisco" for product "Telepresence Video Communication Server Software" | x8.6 Search vendor "Cisco" for product "Telepresence Video Communication Server Software" and version "x8.6" | expressway |
Affected
|