VDB

CVE-2018-15430

CVE-2018-15430 PUBLISHED CVSS 6.5 MEDIUM

A vulnerability in the administrative web interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with user-level privileges on the underlying operating system. The vulnerability is due to insufficient validation of the content of upgrade packages. An attacker could exploit this vulnerability by uploading a malicious archive to the Upgrade page of the administrative web interface. A successful exploit could allow the attacker to execute code with user-level privileges on the underlying operating system.

EPSS 1.50% · 81.5th percentile

Risk Scores

CVSS 2.0
6.5
EPSS Score
1.50%
81.5th percentile

Affected Products

VendorProductVersions
ciscotelepresence_video_communication_serverx7.2.4, x8.10.4, *
CiscoCisco TelePresence Video Communication Server (VCS)n/a

Timeline

  • Oct 3, 2018 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›