5
CVSSv2

CVE-2016-1316

Published: 09/02/2016 Updated: 06/12/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7, as used in conjunction with Jabber Guest, allows remote malicious users to obtain sensitive call-statistics information via a direct request to an unspecified URL, aka Bug ID CSCux73362.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco telepresence video communication server software x8.1.2

cisco telepresence video communication server software x8.2_base

cisco telepresence video communication server software x8.2.2

cisco telepresence video communication server software x8.2.1

cisco telepresence video communication server software x8.6.1

cisco telepresence video communication server software x8.6.0

cisco telepresence video communication server software x8.7_base

cisco telepresence video communication server software x8.1.1

cisco telepresence video communication server software x8.5.3

cisco telepresence video communication server software x8.5.2

cisco telepresence video communication server software x8.1_base

cisco telepresence video communication server software x8.5.1

cisco telepresence video communication server software x8.5.0

Vendor Advisories

Cisco Video Communications Server (VCS), when utilized as part of a Jabber Guest deployment, contains an information disclosure vulnerability that could allow and unauthenticated, remote attacker to gain access to potentially sensitive information The vulnerability exists due to a failure to properly protect an informational URL that contains agg ...