cbcvebase.
CVE-2016-1387
published 2016-05-05

CVE-2016-1387: The XML API in TelePresence Codec (TC) 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, and 7.3.5 and Collaboration Endpoint (CE) 8.0.0, 8.0.1, and 8.1.0 in…

PriorityP265critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
1.78%
75.6th percentile
The XML API in TelePresence Codec (TC) 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, and 7.3.5 and Collaboration Endpoint (CE) 8.0.0, 8.0.1, and 8.1.0 in Cisco TelePresence Software mishandles authentication, which allows remote attackers to execute control commands or make configuration changes via an API request, aka Bug ID CSCuz26935.

Affected

7 ranges
VendorProductVersion rangeFixed in
ciscotelepresence_tc_software
ciscotelepresence_tc_software
ciscotelepresence_tc_software
ciscotelepresence_tc_software
ciscotelepresence_tc_software
ciscotelepresence_tc_software
ciscotelepresence_xml_application_programming_interface

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160504-tpxml
  • Monitor for unauthenticated or anomalous HTTP requests targeting the TelePresence XML API endpoint, which may indicate an authentication bypass attempt.
  • Alert on unauthorized configuration changes or unexpected control commands issued via the XML API, as these are the primary post-exploitation indicators.
  • Focus detection on the XML API surface of Cisco TelePresence TC (versions 7.2.0–7.3.5) and CE (versions 8.0.0–8.1.0) software, as these are the affected attack targets.
  • ·A vendor-confirmed workaround exists for this vulnerability in addition to the software patch; defenders should consult the advisory for workaround details to apply interim mitigations.
  • ·The vulnerability is rooted in improper implementation of authentication mechanisms specifically for the XML API; any detection or hardening strategy must account for this API layer being accessible without valid credentials.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:N/C:P/I:P/A:C
vendor_cisco9.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.