Cisco Telepresence Video Communication Server vulnerabilities

8 known vulnerabilities affecting cisco/cisco_telepresence_video_communication_server.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM6

Vulnerabilities

Page 1 of 1
CVE-2019-12705MEDIUMCVSS 6.1≥ unspecified, < n/a2019-10-16
CVE-2019-12705 [MEDIUM] CWE-79 CVE-2019-12705: A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePrese A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vulnerability is due to insufficient val
cvelistv5nvd
CVE-2019-1845HIGHCVSS 8.6≥ unspecified, < 12.5(1)2019-06-05
CVE-2019-1845 [HIGH] CWE-20 CVE-2019-1845: A vulnerability in the authentication service of the Cisco Unified Communications Manager IM and Pre A vulnerability in the authentication service of the Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, Cisco TelePresence Video Communication Server (VCS), and Cisco Expressway Series could allow an unauthenticated, remote attacker to cause a service outage for users attempting to authenticate, resulting in a denial of servi
cvelistv5nvd
CVE-2019-1872MEDIUMCVSS 5.3≥ unspecified, < X12.52019-06-05
CVE-2019-1872 [MEDIUM] CWE-918 CVE-2019-1872: A vulnerability in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway Series s A vulnerability in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway Series software could allow an unauthenticated, remote attacker to cause an affected system to send arbitrary network requests. The vulnerability is due to improper restrictions on network services in the affected software. An attacker could exploit this vulner
cvelistv5nvd
CVE-2019-1722MEDIUMCVSS 6.5≥ unspecified, < X12.5.12019-04-18
CVE-2019-1722 [MEDIUM] CWE-352 CVE-2019-1722: A vulnerability in the FindMe feature of Cisco Expressway Series and Cisco TelePresence Video Commun A vulnerability in the FindMe feature of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based m
cvelistv5nvd
CVE-2019-1721MEDIUMCVSS 6.5≥ unspecified, < X12.5.12019-04-18
CVE-2019-1721 [MEDIUM] CWE-20 CVE-2019-1721: A vulnerability in the phone book feature of Cisco Expressway Series and Cisco TelePresence Video Co A vulnerability in the phone book feature of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to cause the CPU to increase to 100% utilization, causing a denial of service (DoS) condition on an affected system. The vulnerability is due to improper handling of the XML input. An
cvelistv5nvd
CVE-2019-1720MEDIUMCVSS 4.9≥ unspecified, < X12.5.12019-04-18
CVE-2019-1720 [MEDIUM] CWE-20 CVE-2019-1720: A vulnerability in the XML API of Cisco Expressway Series and Cisco TelePresence Video Communication A vulnerability in the XML API of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to cause the CPU to increase to 100% utilization, causing a denial of service (DoS) condition on an affected system. The vulnerability is due to improper handling of the XML input. An attacker c
cvelistv5nvd
CVE-2019-1679MEDIUMCVSS 5.0≥ unspecified, < XC4.3.42019-02-07
CVE-2019-1679 [MEDIUM] CWE-918 CVE-2019-1679: A vulnerability in the web interface of Cisco TelePresence Conductor, Cisco Expressway Series, and C A vulnerability in the web interface of Cisco TelePresence Conductor, Cisco Expressway Series, and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to trigger an HTTP request from an affected server to an arbitrary host. This type of attack is commonly referred to as server-side request forgery
cvelistv5nvd
CVE-2018-15430HIGHCVSS 7.2vn/a2018-10-05
CVE-2018-15430 [HIGH] CWE-20 CVE-2018-15430: A vulnerability in the administrative web interface of Cisco Expressway Series and Cisco TelePresenc A vulnerability in the administrative web interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with user-level privileges on the underlying operating system. The vulnerability is due to insufficient validation of the content of upgrade packages. An att
cvelistv5nvd