CVE-2014-0675

Cisco TelePresence Video Communication Server - Man-in-the-Middle Attack via Default X.509 Certificate

Title source: llm
STIX 2.1

Description

The Expressway component in Cisco TelePresence Video Communication Server (VCS) uses the same default X.509 certificate across different customers' installations, which makes it easier for remote attackers to conduct man-in-the-middle attacks against SSL sessions by leveraging the certificate's trust relationship, aka Bug ID CSCue07471.

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/65101
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/90650
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/56621
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/102377
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1029682

Scores

EPSS 0.0160
EPSS Percentile 73.3%

Details

CWE
CWE-255
Status published
Products (1)
cisco/telepresence_video_communication_server
Published Jan 23, 2014
Tracked Since Feb 18, 2026