Cisco Telepresence Tc Software vulnerabilities
25 known vulnerabilities affecting cisco/telepresence_tc_software.
Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH15MEDIUM6
Vulnerabilities
Page 2 of 2
CVE-2015-0770P4MEDIUMCVSS 5.0v6.3.0v6.3.1+12 more2015-06-07
CVE-2015-0770 [MEDIUM] CWE-20 CVE-2015-0770: CRLF injection vulnerability in Cisco TelePresence TC 6.x before 6.3.4 and 7.x before 7.3.3 on Integ
CRLF injection vulnerability in Cisco TelePresence TC 6.x before 6.3.4 and 7.x before 7.3.3 on Integrator C SX20 devices allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL, aka Bug ID CSCut79341.
nvd
CVE-2015-0697P4MEDIUMCVSS 5.8v6.0.0v6.0.0-cucm+13 more2015-04-15
CVE-2015-0697 [MEDIUM] CWE-601 CVE-2015-0697: Open redirect vulnerability in the login page in Cisco TC Software before 6.3-26 and 7.x before 7.3.
Open redirect vulnerability in the login page in Cisco TC Software before 6.3-26 and 7.x before 7.3.0 on Cisco TelePresence Collaboration Desk and Room Endpoints devices allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCuq94980.
nvd
CVE-2016-6459P4MEDIUMCVSS 5.5v7.1.0v7.1.1+9 more2016-11-19
CVE-2016-6459 [MEDIUM] CWE-78 CVE-2016-6459: Cisco TelePresence endpoints running either CE or TC software contain a vulnerability that could all
Cisco TelePresence endpoints running either CE or TC software contain a vulnerability that could allow an authenticated, local attacker to execute a local shell command injection. More Information: CSCvb25010. Known Affected Releases: 8.1.x. Known Fixed Releases: 6.3.4 7.3.7 8.2.2 8.3.0.
nvd
CVE-2014-2172P4MEDIUMCVSS 6.6v4.0.0v4.0.1+19 more2014-05-02
CVE-2014-2172 [MEDIUM] CWE-119 CVE-2014-2172: Buffer overflow in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows loc
Buffer overflow in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows local users to gain privileges by leveraging improper handling of the u-boot compiler flag for internal executable files, aka Bug ID CSCub67693.
nvd
CVE-2015-0696P4MEDIUMCVSS 4.3v6.0.0v6.0.0-cucm+12 more2015-04-15
CVE-2015-0696 [MEDIUM] CWE-79 CVE-2015-0696: Cross-site scripting (XSS) vulnerability in the login page in Cisco TC Software before 7.1.0 on Cisc
Cross-site scripting (XSS) vulnerability in the login page in Cisco TC Software before 7.1.0 on Cisco TelePresence Collaboration Desk and Room Endpoints devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuq94977.
nvd
← Previous2 / 2