CVE-2015-0653
published 2015-03-13CVE-2015-0653: The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before X8.2.2…
PriorityP355critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
4.34%
90.1th percentile
The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before X8.2.2 and Cisco TelePresence Conductor before X2.3.1 and XC2.4 before XC2.4.1 allows remote attackers to bypass authentication via crafted login parameters, aka Bug IDs CSCur02680 and CSCur05556.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | expressway_software | >= x7.2 < x7.2.4 | x7.2.4 |
| cisco | expressway_software | >= x8.1 < x8.1.2 | x8.1.2 |
| cisco | expressway_software | >= x8.2 < x8.2.2 | x8.2.2 |
| cisco | telepresence_conductor | — | — |
| cisco | telepresence_conductor | >= x2.3 < x2.3.1 | x2.3.1 |
| cisco | telepresence_conductor | >= xc2.4 < xc2.4.1 | xc2.4.1 |
| cisco | telepresence_video_communication_server_software | >= x7.2 < x7.2.4 | x7.2.4 |
| cisco | telepresence_video_communication_server_software | >= x8.1 < x8.1.2 | x8.1.2 |
| cisco | telepresence_video_communication_server_software | >= x8.2 < x8.2.2 | x8.2.2 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco TelePresence Video Communication Server, Cisco Expressway, and Cisco TelePresence Conductor
vendor_cisco·2015-03-11·CVSS 10.0
CVE-2015-0652 [CRITICAL] CWE-287 Multiple Vulnerabilities in Cisco TelePresence Video Communication Server, Cisco Expressway, and Cisco TelePresence Conductor
Multiple Vulnerabilities in Cisco TelePresence Video Communication Server, Cisco Expressway, and Cisco TelePresence Conductor
Cisco TelePresence Video Communication Server (VCS), Cisco Expressway and Cisco TelePresence Conductor contain the following vulnerabilities:
SDP Media Description Denial of Service Vulnerability
Authentication Bypass Vulnerability
Successful exploitation of the SDP Media Description Denial of Service Vulnerability may
cause the affected system to reload.
Successful exploitation of the Authentication Bypass Vulnerability may allow an attacker to
bypass authentication and log in to the system with the privileges of an administrator.
Cisco has released software updates that address these vulnerabilities. Workarounds that mitigate these vulnerabilities are not av
Cisco
Multiple Vulnerabilities in Cisco TelePresence Video Communication Server, Cisco Expressway, and Cisco TelePresence Conductor
vendor_cisco
CVE-2015-0653 Multiple Vulnerabilities in Cisco TelePresence Video Communication Server, Cisco Expressway, and Cisco TelePresence Conductor
CVE-2015-0653: Multiple Vulnerabilities in Cisco TelePresence Video Communication Server, Cisco Expressway, and Cisco TelePresence Conductor
Cisco TelePresence Video Communication Server (VCS), Cisco Expressway and Cisco TelePresence Conductor contain the following vulnerabilities: SDP Media Description Denial of Service Vulnerability Authentication Bypass Vulnerability Successful exploitation of the SDP Media Description Denial of Service Vulnerability may cause the affected system to reload. Successful exploitation of the Authentication Bypass Vulnerability may allow an attacker to bypass authentication and log in to the system with the privileges of an administrator. Cisco has released software updates that address these vulnerabilities.
CWE: CWE-287, CWE-399, CWE-287, CWE-399
Bug IDs:
GHSA
GHSA-283q-v54f-pc9w: The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7
ghsa_unreviewed·2022-05-14
CVE-2015-0653 [HIGH] CWE-287 GHSA-283q-v54f-pc9w: The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7
The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before X8.2.2 and Cisco TelePresence Conductor before X2.3.1 and XC2.4 before XC2.4.1 allows remote attackers to bypass authentication via crafted login parameters, aka Bug IDs CSCur02680 and CSCur05556.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-03-13
Published