cbcvebase.
CVE-2015-0653
published 2015-03-13

CVE-2015-0653: The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before X8.2.2…

PriorityP355critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
4.34%
90.1th percentile
The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before X8.2.2 and Cisco TelePresence Conductor before X2.3.1 and XC2.4 before XC2.4.1 allows remote attackers to bypass authentication via crafted login parameters, aka Bug IDs CSCur02680 and CSCur05556.

Affected

9 ranges
VendorProductVersion rangeFixed in
ciscoexpressway_software>= x7.2 < x7.2.4x7.2.4
ciscoexpressway_software>= x8.1 < x8.1.2x8.1.2
ciscoexpressway_software>= x8.2 < x8.2.2x8.2.2
ciscotelepresence_conductor
ciscotelepresence_conductor>= x2.3 < x2.3.1x2.3.1
ciscotelepresence_conductor>= xc2.4 < xc2.4.1xc2.4.1
ciscotelepresence_video_communication_server_software>= x7.2 < x7.2.4x7.2.4
ciscotelepresence_video_communication_server_software>= x8.1 < x8.1.2x8.1.2
ciscotelepresence_video_communication_server_software>= x8.2 < x8.2.2x8.2.2

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.