Cisco
Cisco Telepresence Video Communication Server Software: vulnerabilidades y CVE
Cisco Telepresence Video Communication Server Software tiene 29 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE29
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2016-1444 | Media (6.5) | 1.2% | — | 7 jul 2016 | The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7 and Expressway X8.1 through X8.6 mishandles certificates, which allows remote attackers to bypass… |
| CVE-2016-1338 | Media (6.5) | 1.6% | — | 12 mar 2016 | Cisco TelePresence Video Communication Server (VCS) X8.5.1 and X8.5.2 allows remote authenticated users to cause a denial of service (VoIP outage) via a crafted SIP message, aka Bug ID CSCuu43026. |
| CVE-2016-1316 | Media (5.3) | 1.5% | — | 9 feb 2016 | Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7, as used in conjunction with Jabber Guest, allows remote attackers to obtain sensitive call-statistics information via a direct request to an… |
| CVE-2015-6410 | Media (4) | 1.7% | — | 14 dic 2015 | The Mobile and Remote Access (MRA) services implementation in Cisco Unified Communications Manager mishandles edge-device identity validation, which allows remote attackers to bypass intended call-reception and… |
| CVE-2015-6414 | Baja (2.1) | 0.23% | — | 13 dic 2015 | Cisco TelePresence Video Communication Server (VCS) X8.6 uses the same encryption key across different customers' installations, which makes it easier for local users to defeat cryptographic protection mechanisms by… |
| CVE-2015-6413 | Media (4) | 1.7% | — | 13 dic 2015 | Cisco TelePresence Video Communication Server (VCS) Expressway X8.6 allows remote authenticated users to bypass intended read-only restrictions and upload Tandberg Linux Package (TLP) files by visiting an administrative… |
| CVE-2015-6376 | Media (6.8) | 0.59% | — | 21 nov 2015 | Cross-site request forgery (CSRF) vulnerability in Cisco TelePresence Video Communication Server (VCS) X8.5.1 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuv72412. |
| CVE-2015-6318 | Media (6.9) | 0.36% | — | 12 oct 2015 | Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.1 and X8.5.2 allows local users to write to arbitrary files via an unspecified symlink attack, aka Bug ID CSCuv11969. |
| CVE-2015-4325 | Media (6.9) | 0.39% | — | 12 oct 2015 | The process-management implementation in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to gain privileges by terminating a firestarter.py supervised process and then triggering… |
| CVE-2015-4330 | Media (6.9) | 0.54% | — | 2 sept 2015 | A local file script in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to gain privileges for OS command execution via invalid parameters, aka Bug ID CSCuv10556. |
| CVE-2015-6261 | Media (4) | 1.5% | — | 26 ago 2015 | Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows remote authenticated users to bypass intended access restrictions and read configuration files by leveraging the Mobile and Remote Access… |
| CVE-2015-4318 | Media (5) | 2.4% | — | 20 ago 2015 | Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows remote attackers to cause a denial of service via invalid variables in a GET request, aka Bug ID CSCuv40528. |
| CVE-2015-4329 | Media (6.5) | 2.3% | — | 20 ago 2015 | The administrator web interface in Cisco TelePresence Video Communication Server (VCS) X8.5.2 allows remote authenticated users to execute arbitrary OS commands via crafted HTTP requests, aka Bug ID CSCuv11796. |
| CVE-2015-4319 | Media (5.5) | 2.4% | — | 20 ago 2015 | The password-change feature in the administrative web interface in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.1 improperly performs authorization, which allows remote authenticated users to… |
| CVE-2015-4316 | Media (5.5) | 1.9% | — | 20 ago 2015 | The Mobile and Remote Access (MRA) endpoint-validation feature in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 improperly validates the phone line used for registration, which allows remote… |
| CVE-2015-4303 | Media (6.5) | 2.3% | — | 20 ago 2015 | Cisco TelePresence Video Communication Server (VCS) X8.5.2 allows remote authenticated users to execute arbitrary commands in the context of the nobody user account via an unspecified web-page parameter, aka Bug ID… |
| CVE-2015-4328 | Media (4) | 2.0% | — | 20 ago 2015 | Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 improperly checks for a user account's read-only attribute, which allows remote authenticated users to execute arbitrary OS commands via crafted HTTP… |
| CVE-2015-4327 | Alta (7.2) | 0.41% | — | 20 ago 2015 | The CLI in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to obtain root privileges by writing script arguments to an unspecified file, aka Bug ID CSCuv12542. |
| CVE-2015-4320 | Media (4) | 1.6% | — | 20 ago 2015 | The Configuration Log File component in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows remote authenticated users to obtain sensitive information by reading a log file, aka Bug ID… |
| CVE-2015-4317 | Media (5) | 2.6% | — | 20 ago 2015 | Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows remote attackers to cause a denial of service via invalid variables in an authentication packet, aka Bug ID CSCuv40469. |
| CVE-2015-4315 | Media (5.5) | 1.9% | — | 20 ago 2015 | The Call Policy Configuration page in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.3 improperly validates external DTDs, which allows remote authenticated users to read arbitrary files or cause a… |
| CVE-2015-4314 | Media (4) | 1.3% | — | 20 ago 2015 | The System Snapshot feature in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.1 allows remote authenticated users to obtain sensitive password-hash information by reading the snapshot file, aka Bug… |
| CVE-2015-0772 | Alta (7.1) | 1.9% | — | 12 jun 2015 | Cisco TelePresence Video Communication Server (VCS) X8.5RC4 allows remote attackers to cause a denial of service (CPU consumption or device outage) via a crafted SDP parameter-negotiation request in an SDP session… |
| CVE-2015-0653 | Alta (10) | 4.3% | — | 13 mar 2015 | The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before X8.2.2 and Cisco TelePresence Conductor before X2.3.1 and XC2.4… |
| CVE-2015-0652 | Alta (7.8) | 1.9% | — | 13 mar 2015 | The Session Description Protocol (SDP) implementation in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X8.2 and Cisco TelePresence Conductor before XC2.4 allows remote attackers to… |
| CVE-2014-3370 | Alta (7.1) | 2.3% | — | 19 oct 2014 | Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allow remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug IDs CSCum60442 and… |
| CVE-2014-3369 | Alta (7.1) | 2.4% | — | 19 oct 2014 | The SIP IX implementation in Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allows remote attackers to cause a denial of service (device reload) via crafted SDP packets, aka… |
| CVE-2014-3368 | Alta (7.8) | 3.9% | — | 19 oct 2014 | Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.2 allow remote attackers to cause a denial of service (device reload) via a high rate of crafted packets, aka Bug ID CSCui06507. |
| CVE-2014-0662 | Alta (7.1) | 1.9% | — | 22 ene 2014 | The SIP module in Cisco TelePresence Video Communication Server (VCS) before 8.1 allows remote attackers to cause a denial of service (process failure) via a crafted SDP message, aka Bug ID CSCue97632. |