The Mobile and Remote Access (MRA) endpoint-validation feature in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 improperly validates the phone line used for registration, which allows remote authenticated users to conduct impersonation attacks via a crafted registration, aka Bug ID CSCuv40396.
2015-08-20T10:59:07.903
2025-04-12T10:46:40.837
Deferred
CVSSv2: 5.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:P
8.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cisco | telepresence_video_communication_server_software | x8.5.2 | Yes |