CVE-2015-0697
published 2015-04-15CVE-2015-0697: Open redirect vulnerability in the login page in Cisco TC Software before 6.3-26 and 7.x before 7.3.0 on Cisco TelePresence Collaboration Desk and Room…
PriorityP425medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
1.87%
76.9th percentile
Open redirect vulnerability in the login page in Cisco TC Software before 6.3-26 and 7.x before 7.3.0 on Cisco TelePresence Collaboration Desk and Room Endpoints devices allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCuq94980.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_cisco5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q74v-5rv8-9qjj: Open redirect vulnerability in the login page in Cisco TC Software before 6
ghsa_unreviewed·2022-05-17
CVE-2015-0697 [MEDIUM] CWE-601 GHSA-q74v-5rv8-9qjj: Open redirect vulnerability in the login page in Cisco TC Software before 6
Open redirect vulnerability in the login page in Cisco TC Software before 6.3-26 and 7.x before 7.3.0 on Cisco TelePresence Collaboration Desk and Room Endpoints devices allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCuq94980.
Cisco
Cisco TelePresence Collaboration Desk and Room Endpoints HTML Redirect Vulnerability
vendor_cisco·2015-04-14·CVSS 5.8
CVE-2015-0697 [MEDIUM] CWE-20 Cisco TelePresence Collaboration Desk and Room Endpoints HTML Redirect Vulnerability
Cisco TelePresence Collaboration Desk and Room Endpoints HTML Redirect Vulnerability
A vulnerability within the login page of the web user interface of Cisco TelePresence Collaboration Desk and Room Endpoints devices running TC Software could allow an unauthenticated, remote attacker to conduct HTML redirection attacks.
The vulnerability is due to improper input validation of certain parameters passed to an affected device. An unauthenticated, remote attacker could exploit this vulnerability by convincing a user to follow a malicious link or visit an attacker-controlled site. A successful exploit could allow the attacker the ability to gain access to sensitive information by impersonating the targeted device, which could be leveraged to conduct further attacks.
Cisco has confirmed the v
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-0340 flash-plugin: file upload restriction bypass (APSB15-05)
bugzilla·2015-03-13·CVSS 5.0
CVE-2015-0340 [MEDIUM] CVE-2015-0340 flash-plugin: file upload restriction bypass (APSB15-05)
CVE-2015-0340 flash-plugin: file upload restriction bypass (APSB15-05)
Adobe has released Flash Player 11.2.202.451 for Linux via APSB15-05 to correct the following flaw:
* These updates resolve a vulnerability that could lead to a file upload restriction bypass (CVE-2015-0340).
External References:
https://helpx.adobe.com/security/products/flash-player/apsb15-05.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0697 https://rhn.redhat.com/errata/RHSA-2015-0697.html
Bugzilla
CVE-2015-0337 flash-plugin: cross-domain policy bypass (APSB15-05)
bugzilla·2015-03-13·CVSS 5.0
CVE-2015-0337 [MEDIUM] CVE-2015-0337 flash-plugin: cross-domain policy bypass (APSB15-05)
CVE-2015-0337 flash-plugin: cross-domain policy bypass (APSB15-05)
Adobe has released Flash Player 11.2.202.451 for Linux via APSB15-05 to correct the following flaw:
* These updates resolve a vulnerability that could lead to a cross-domain policy bypass (CVE-2015-0337).
External References:
https://helpx.adobe.com/security/products/flash-player/apsb15-05.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 5
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0697 https://rhn.redhat.com/errata/RHSA-2015-0697.html
2015-04-15
Published