cisco-sa-20160208-vcs
Cisco Video Communications Server Information Disclosure Vulnerability
Medium · Updated · Cisco
1 product with CSAF evidence
Cisco Video Communications Server (VCS), when utilized as part of a Jabber Guest deployment, contains an information disclosure vulnerability that could allow and unauthenticated, remote attacker to gain access to potentially sensitive information. The vulnerability exists due to a failure to properly protect an informational URL that contains aggregated call statistics. An attacker that knows the URL could submit a request to retrieve the page containing the information. Cisco has not released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.