CVE-2015-4271
published 2015-07-15CVE-2015-4271: Cisco TelePresence TC before 7.3.4 on Integrator C devices allows remote attackers to bypass authentication via vectors involving multiple request parameters…
PriorityP342medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
2.36%
81.9th percentile
Cisco TelePresence TC before 7.3.4 on Integrator C devices allows remote attackers to bypass authentication via vectors involving multiple request parameters, aka Bug ID CSCuv00604.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vendor_cisco6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6r89-gjq3-65ww: Cisco TelePresence TC before 7
ghsa_unreviewed·2022-05-17
CVE-2015-4271 [MEDIUM] CWE-284 GHSA-6r89-gjq3-65ww: Cisco TelePresence TC before 7
Cisco TelePresence TC before 7.3.4 on Integrator C devices allows remote attackers to bypass authentication via vectors involving multiple request parameters, aka Bug ID CSCuv00604.
Cisco
Cisco TelePresence Integrator C Series Multiple Request Parameter Vulnerability
vendor_cisco·2015-07-14·CVSS 6.4
CVE-2015-4271 [MEDIUM] CWE-287 Cisco TelePresence Integrator C Series Multiple Request Parameter Vulnerability
Cisco TelePresence Integrator C Series Multiple Request Parameter Vulnerability
A vulnerability in Cisco TelePresence Integrator C Series could allow an unauthenticated, remote attacker to bypass authentication.
The vulnerability is due to insufficient validation of user-supplied values. An attacker could exploit this vulnerability by sending multiple request parameters to an affected device.
Cisco has confirmed the vulnerability and released software updates.
A successful exploit of this vulnerability could allow an attacker to bypass authentication and gain unauthorized access to the targeted device. If successful, the attacker could have the ability to conduct further attacks, which may impact the confidentiality, integrity, or availability of the device.
Cisco indicates through t
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-07-15
Published