CVE-2018-15430: Cisco Telepresence Video Communication Server

High severity, CVSS 7.2. EPSS: 2.9% chance of exploitation in the next 30 days.

A vulnerability in the administrative web interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with user-level privileges on the underlying operating system. The vulnerability is due to insufficient validation of the content of upgrade packages. An attacker could exploit this vulnerability by uploading a malicious archive to the Upgrade page of the administrative web interface. A successful exploit could allow the attacker to execute code with user-level privileges on the underlying operating system.

Affected products

  • Cisco Telepresence Video Communication Server: version x7.2.4 only; version x8.9.2 only; version x8.10.4 only

Published 2018-10-05. Last modified 2026-06-17.