// For flags

CVE-2016-1444

 

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7 and Expressway X8.1 through X8.6 mishandles certificates, which allows remote attackers to bypass authentication via an arbitrary trusted certificate, aka Bug ID CSCuz64601.

El componente Mobile and Remote Access (MRA) en Cisco TelePresence Video Communication Server (VCS) X8.1 hasta la versión X8.7 y Expressway X8.1 hasta la versión X8.6 no maneja correctamente los certificados, lo que permite a atacantes remotos eludir la autenticación a través de un certificado confiable manipulado, también conocido como Bug ID CSCuz64601.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2016-01-04 CVE Reserved
  • 2016-07-07 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-20: Improper Input Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Telepresence Video Communication Server
Search vendor "Cisco" for product "Telepresence Video Communication Server"
x8.1
Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.1"
-
Affected
Cisco
Search vendor "Cisco"
Telepresence Video Communication Server
Search vendor "Cisco" for product "Telepresence Video Communication Server"
x8.1.1
Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.1.1"
-
Affected
Cisco
Search vendor "Cisco"
Telepresence Video Communication Server
Search vendor "Cisco" for product "Telepresence Video Communication Server"
x8.1.2
Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.1.2"
-
Affected
Cisco
Search vendor "Cisco"
Telepresence Video Communication Server
Search vendor "Cisco" for product "Telepresence Video Communication Server"
x8.2
Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.2"
-
Affected
Cisco
Search vendor "Cisco"
Telepresence Video Communication Server
Search vendor "Cisco" for product "Telepresence Video Communication Server"
x8.2.1
Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.2.1"
-
Affected
Cisco
Search vendor "Cisco"
Telepresence Video Communication Server
Search vendor "Cisco" for product "Telepresence Video Communication Server"
x8.2.2
Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.2.2"
-
Affected
Cisco
Search vendor "Cisco"
Telepresence Video Communication Server
Search vendor "Cisco" for product "Telepresence Video Communication Server"
x8.5
Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.5"
rc4
Affected
Cisco
Search vendor "Cisco"
Telepresence Video Communication Server
Search vendor "Cisco" for product "Telepresence Video Communication Server"
x8.5.0
Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.5.0"
-
Affected
Cisco
Search vendor "Cisco"
Telepresence Video Communication Server
Search vendor "Cisco" for product "Telepresence Video Communication Server"
x8.5.1
Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.5.1"
-
Affected
Cisco
Search vendor "Cisco"
Telepresence Video Communication Server
Search vendor "Cisco" for product "Telepresence Video Communication Server"
x8.5.2
Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.5.2"
-
Affected
Cisco
Search vendor "Cisco"
Telepresence Video Communication Server
Search vendor "Cisco" for product "Telepresence Video Communication Server"
x8.5.3
Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.5.3"
-
Affected
Cisco
Search vendor "Cisco"
Telepresence Video Communication Server
Search vendor "Cisco" for product "Telepresence Video Communication Server"
x8.6.0
Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.6.0"
-
Affected
Cisco
Search vendor "Cisco"
Telepresence Video Communication Server
Search vendor "Cisco" for product "Telepresence Video Communication Server"
x8.6.1
Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.6.1"
-
Affected
Cisco
Search vendor "Cisco"
Telepresence Video Communication Server
Search vendor "Cisco" for product "Telepresence Video Communication Server"
x8.7
Search vendor "Cisco" for product "Telepresence Video Communication Server" and version "x8.7"
-
Affected
Cisco
Search vendor "Cisco"
Telepresence Video Communication Server Software
Search vendor "Cisco" for product "Telepresence Video Communication Server Software"
x8.5.1
Search vendor "Cisco" for product "Telepresence Video Communication Server Software" and version "x8.5.1"
expressway
Affected
Cisco
Search vendor "Cisco"
Telepresence Video Communication Server Software
Search vendor "Cisco" for product "Telepresence Video Communication Server Software"
x8.5.2
Search vendor "Cisco" for product "Telepresence Video Communication Server Software" and version "x8.5.2"
expressway
Affected
Cisco
Search vendor "Cisco"
Telepresence Video Communication Server Software
Search vendor "Cisco" for product "Telepresence Video Communication Server Software"
x8.5.3
Search vendor "Cisco" for product "Telepresence Video Communication Server Software" and version "x8.5.3"
expressway
Affected
Cisco
Search vendor "Cisco"
Telepresence Video Communication Server Software
Search vendor "Cisco" for product "Telepresence Video Communication Server Software"
x8.6
Search vendor "Cisco" for product "Telepresence Video Communication Server Software" and version "x8.6"
expressway
Affected