CVE-2016-1387
published 2016-05-05CVE-2016-1387: The XML API in TelePresence Codec (TC) 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, and 7.3.5 and Collaboration Endpoint (CE) 8.0.0, 8.0.1, and 8.1.0 in…
PriorityP265critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
1.78%
75.6th percentile
The XML API in TelePresence Codec (TC) 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, and 7.3.5 and Collaboration Endpoint (CE) 8.0.0, 8.0.1, and 8.1.0 in Cisco TelePresence Software mishandles authentication, which allows remote attackers to execute control commands or make configuration changes via an API request, aka Bug ID CSCuz26935.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_xml_application_programming_interface | — | — |
Detection & IOCsextracted from sources · hover to see the quote
urlhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160504-tpxml↗
- →Monitor for unauthenticated or anomalous HTTP requests targeting the TelePresence XML API endpoint, which may indicate an authentication bypass attempt. ↗
- →Alert on unauthorized configuration changes or unexpected control commands issued via the XML API, as these are the primary post-exploitation indicators. ↗
- →Focus detection on the XML API surface of Cisco TelePresence TC (versions 7.2.0–7.3.5) and CE (versions 8.0.0–8.1.0) software, as these are the affected attack targets. ↗
- ·A vendor-confirmed workaround exists for this vulnerability in addition to the software patch; defenders should consult the advisory for workaround details to apply interim mitigations. ↗
- ·The vulnerability is rooted in improper implementation of authentication mechanisms specifically for the XML API; any detection or hardening strategy must account for this API layer being accessible without valid credentials. ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:N/C:P/I:P/A:C
vendor_cisco9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco TelePresence XML Application Programming Interface Authentication Bypass Vulnerability
vendor_cisco·2016-05-04·CVSS 9.0
CVE-2016-1387 [CRITICAL] Cisco TelePresence XML Application Programming Interface Authentication Bypass Vulnerability
Cisco TelePresence XML Application Programming Interface Authentication Bypass Vulnerability
A vulnerability in the XML application programming interface (API) of Cisco TelePresence Codec (TC) and Collaboration Endpoint (CE) Software could allow an unauthenticated, remote attacker to bypass authentication and access a targeted system through the API.
The vulnerability is due to improper implementation of authentication mechanisms for the XML API of the affected software. An attacker could exploit this vulnerability by sending a crafted HTTP request to the XML API. A successful exploit could allow the attacker to perform unauthorized configuration changes or issue control commands to the affected system by using the API.
Cisco has released software updates that address this vulnerability
Cisco
Cisco TelePresence XML Application Programming Interface Authentication Bypass Vulnerability
vendor_cisco
CVE-2016-1387 Cisco TelePresence XML Application Programming Interface Authentication Bypass Vulnerability
CVE-2016-1387: Cisco TelePresence XML Application Programming Interface Authentication Bypass Vulnerability
A vulnerability in the XML application programming interface (API) of Cisco TelePresence Codec (TC) and Collaboration Endpoint (CE) Software could allow an unauthenticated, remote attacker to bypass authentication and access a targeted system through the API. The vulnerability is due to improper implementation of authentication mechanisms for the XML API of the affected software. An attacker could exploit this vulnerability by sending a crafted HTTP request to the XML API. A successful exploit could allow the attacker to perform unauthorized configuration changes or issue control commands to the affected system by using the API. Cisco has released software updates that address this v
GHSA
GHSA-p6fp-5rvv-m3w2: The XML API in TelePresence Codec (TC) 7
ghsa_unreviewed·2022-05-17
CVE-2016-1387 [CRITICAL] CWE-287 GHSA-p6fp-5rvv-m3w2: The XML API in TelePresence Codec (TC) 7
The XML API in TelePresence Codec (TC) 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, and 7.3.5 and Collaboration Endpoint (CE) 8.0.0, 8.0.1, and 8.1.0 in Cisco TelePresence Software mishandles authentication, which allows remote attackers to execute control commands or make configuration changes via an API request, aka Bug ID CSCuz26935.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-05-05
Published