CVE-2015-0696
published 2015-04-15CVE-2015-0696: Cross-site scripting (XSS) vulnerability in the login page in Cisco TC Software before 7.1.0 on Cisco TelePresence Collaboration Desk and Room Endpoints…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.55%
72.1th percentile
Cross-site scripting (XSS) vulnerability in the login page in Cisco TC Software before 7.1.0 on Cisco TelePresence Collaboration Desk and Room Endpoints devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuq94977.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Cisco TelePresence Products Cross-Site Scripting Vulnerability
vendor_cisco·2015-04-14·CVSS 4.3
CVE-2015-0696 [MEDIUM] CWE-79 Multiple Cisco TelePresence Products Cross-Site Scripting Vulnerability
Multiple Cisco TelePresence Products Cross-Site Scripting Vulnerability
A vulnerability within the login page of the web user interface of Cisco TelePresence Collaboration Desk and Room Endpoints devices running TC Software could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks.
The vulnerability is due to improper input validation of certain parameters passed to an affected device. An unauthenticated, remote attacker could exploit this vulnerability by convincing a user to follow a malicious link or visit an attacker-controlled site. A successful exploit could allow the attacker the ability to gain access to sensitive information or modify the settings of the device.
Cisco has confirmed the vulnerability and released software updates.
To exploit the v
GHSA
GHSA-h6q2-vv4r-j9g4: Cross-site scripting (XSS) vulnerability in the login page in Cisco TC Software before 7
ghsa_unreviewed·2022-05-17
CVE-2015-0696 [MEDIUM] CWE-79 GHSA-h6q2-vv4r-j9g4: Cross-site scripting (XSS) vulnerability in the login page in Cisco TC Software before 7
Cross-site scripting (XSS) vulnerability in the login page in Cisco TC Software before 7.1.0 on Cisco TelePresence Collaboration Desk and Room Endpoints devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuq94977.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-04-15
Published