CVE-2015-6414
CVE-2015-6414 is a low-severity vulnerability in Cisco Telepresence Video Communication Server Software with a CVSS 2.0 base score of 2.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-200.
Key facts
- Severity: Low (CVSS 2.0 base score 2.1)
- EPSS exploit prediction: 0% (13th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-200
- Affected product: Cisco Telepresence Video Communication Server Software
- Published:
- Last modified:
Description
Cisco TelePresence Video Communication Server (VCS) X8.6 uses the same encryption key across different customers' installations, which makes it easier for local users to defeat cryptographic protection mechanisms by leveraging knowledge of a key from another installation, aka Bug ID CSCuw64516.
Frequently asked questions
- What is CVE-2015-6414?
- Cisco TelePresence Video Communication Server (VCS) X8.6 uses the same encryption key across different customers' installations, which makes it easier for local users to defeat cryptographic protection mechanisms by leveraging knowledge of a key from another installation, aka Bug ID CSCuw64516.
- How severe is CVE-2015-6414?
- CVE-2015-6414 has a CVSS 2.0 base score of 2.1, rated low severity.
- Is CVE-2015-6414 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (13th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2015-6414?
- CVE-2015-6414 affects Cisco Telepresence Video Communication Server Software. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2015-6414?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2015-6414 published?
- CVE-2015-6414 was published on 2015-12-13 and last updated on 2026-06-17.
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151210-tvcs
- http://www.securityfocus.com/bid/79065
- http://www.securitytracker.com/id/1034429
Affected products (1)
- cpe:2.3:a:cisco:telepresence_video_communication_server_software:x8.6:*:*:*:*:*:*:*
More vulnerabilities in Cisco Telepresence Video Communication Server Software
- CVE-2015-0653 — Critical (CVSS 10.0): The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8…
- CVE-2015-0652 — High (CVSS 7.8): The Session Description Protocol (SDP) implementation in Cisco TelePresence Video Communication Server (VCS) and Cisco…
- CVE-2014-3368 — High (CVSS 7.8): Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.2 allow remote attackers to cause…
- CVE-2015-4327 — High (CVSS 7.2): The CLI in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to obtain root…
- CVE-2015-0772 — High (CVSS 7.1): Cisco TelePresence Video Communication Server (VCS) X8.5RC4 allows remote attackers to cause a denial of service (CPU…
- CVE-2014-3370 — High (CVSS 7.1): Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allow remote attackers to…
All CVEs affecting Cisco Telepresence Video Communication Server Software →
Other CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) vulnerabilities
- CVE-2026-92960 — Critical (CVSS 10.0): vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing…
- CVE-2026-92947 — Critical (CVSS 10.0): vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by…
- CVE-2026-70478 — Critical (CVSS 10.0): Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST…
- CVE-2026-27604 — Critical (CVSS 10.0): FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version…
- CVE-2026-40965 — Critical (CVSS 10.0): Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a…
- CVE-2026-42826 — Critical (CVSS 10.0): Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose…
Browse all CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) vulnerabilities →