CVE-2014-0675
Cisco TelePresence Video Communication Server - Man-in-the-Middle Attack via Default X.509 Certificate
Title source: llmDescription
The Expressway component in Cisco TelePresence Video Communication Server (VCS) uses the same default X.509 certificate across different customers' installations, which makes it easier for remote attackers to conduct man-in-the-middle attacks against SSL sessions by leveraging the certificate's trust relationship, aka Bug ID CSCue07471.
References (7)
Core 7
Core References
Vendor Advisory x_refsource_confirm
http://tools.cisco.com/security/center/viewAlert.x?alertId=32540
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/65101
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/90650
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/56621
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/102377
Vendor Advisory vendor-advisory
x_refsource_cisco
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0675
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1029682
Scores
EPSS
0.0160
EPSS Percentile
73.3%
Details
CWE
CWE-255
Status
published
Products (1)
cisco/telepresence_video_communication_server
Published
Jan 23, 2014
Tracked Since
Feb 18, 2026