CVE-2015-4315
Last modified
CVE-2015-4315 is a vulnerability of currently unknown severity. The Call Policy Configuration page in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.3 improperly validates external DTDs, which allows remote authenticated users to read arbitrary files or cause a denial of service via a crafted XML document, aka Bug ID CSCuv31853.. EPSS estimates a 1.87% chance of exploitation in the next 30 days.
Description
The Call Policy Configuration page in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.3 improperly validates external DTDs, which allows remote authenticated users to read arbitrary files or cause a denial of service via a crafted XML document, aka Bug ID CSCuv31853.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Telepresence Video Communication Server Software | x8.5.3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-4315?
How severe is CVE-2015-4315?
How do I fix CVE-2015-4315?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-4305The web framework in Cisco Prime Collaboration Assurance bef…
- CVE-2015-4306The web framework in Cisco Prime Collaboration Assurance bef…
- CVE-2015-4307The web framework in Cisco Prime Collaboration Provisioning …
- CVE-2015-4308The webGUI configuration-export feature in Cisco Edge Bluebi…
- CVE-2015-4310Multiple cross-site scripting (XSS) vulnerabilities in Cisco…
- CVE-2015-4314The System Snapshot feature in Cisco TelePresence Video Comm…
- CVE-2015-4316The Mobile and Remote Access (MRA) endpoint-validation featu…
- CVE-2015-4317Cisco TelePresence Video Communication Server (VCS) Expressw…
- CVE-2015-4318Cisco TelePresence Video Communication Server (VCS) Expressw…
- CVE-2015-4319The password-change feature in the administrative web interf…
- CVE-2015-4320The Configuration Log File component in Cisco TelePresence V…
- CVE-2015-4321The Unicast Reverse Path Forwarding (uRPF) implementation in…
Are you affected by CVE-2015-4315?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
