CVE-2015-0770
published 2015-06-07CVE-2015-0770: CRLF injection vulnerability in Cisco TelePresence TC 6.x before 6.3.4 and 7.x before 7.3.3 on Integrator C SX20 devices allows remote attackers to inject…
PriorityP428medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.75%
75.3th percentile
CRLF injection vulnerability in Cisco TelePresence TC 6.x before 6.3.4 and 7.x before 7.3.3 on Integrator C SX20 devices allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL, aka Bug ID CSCut79341.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco TelePresence HTTP Response Splitting Vulnerability
vendor_cisco·2015-06-05·CVSS 5.0
CVE-2015-0770 [MEDIUM] CWE-20 Cisco TelePresence HTTP Response Splitting Vulnerability
Cisco TelePresence HTTP Response Splitting Vulnerability
A vulnerability in Cisco TelePresence Collaboration Desk and Room Endpoints running TC Software could allow an unauthenticated, remote attacker to conduct HTTP response splitting attacks.
The vulnerability is due to insufficient user input sanitization performed by the affected software while processing HTTP requests. An unauthenticated, remote attacker could exploit this vulnerability by convincing a user to follow a malicious link. If successful, the attacker could conduct HTTP response splitting attacks.
Cisco has confirmed the vulnerability and released software updates.
To exploit the vulnerability, the attacker may provide a link that
directs a user to a malicious site and use misleading language or
instructions to persuad
GHSA
GHSA-pgxq-frjh-qv78: CRLF injection vulnerability in Cisco TelePresence TC 6
ghsa_unreviewed·2022-05-17
CVE-2015-0770 [MEDIUM] CWE-20 GHSA-pgxq-frjh-qv78: CRLF injection vulnerability in Cisco TelePresence TC 6
CRLF injection vulnerability in Cisco TelePresence TC 6.x before 6.3.4 and 7.x before 7.3.3 on Integrator C SX20 devices allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL, aka Bug ID CSCut79341.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-06-07
Published