cbcvebase.

Cisco Telepresence Tc Software vulnerabilities

25 known vulnerabilities affecting cisco/telepresence_tc_software.

Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH15MEDIUM6

Vulnerabilities

Page 2 of 2
CVE-2015-0770P4MEDIUMCVSS 5.0v6.3.0v6.3.1+12 more2015-06-07
CVE-2015-0770 [MEDIUM] CWE-20 CVE-2015-0770: CRLF injection vulnerability in Cisco TelePresence TC 6.x before 6.3.4 and 7.x before 7.3.3 on Integ CRLF injection vulnerability in Cisco TelePresence TC 6.x before 6.3.4 and 7.x before 7.3.3 on Integrator C SX20 devices allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL, aka Bug ID CSCut79341.
nvd
CVE-2015-0697P4MEDIUMCVSS 5.8v6.0.0v6.0.0-cucm+13 more2015-04-15
CVE-2015-0697 [MEDIUM] CWE-601 CVE-2015-0697: Open redirect vulnerability in the login page in Cisco TC Software before 6.3-26 and 7.x before 7.3. Open redirect vulnerability in the login page in Cisco TC Software before 6.3-26 and 7.x before 7.3.0 on Cisco TelePresence Collaboration Desk and Room Endpoints devices allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCuq94980.
nvd
CVE-2016-6459P4MEDIUMCVSS 5.5v7.1.0v7.1.1+9 more2016-11-19
CVE-2016-6459 [MEDIUM] CWE-78 CVE-2016-6459: Cisco TelePresence endpoints running either CE or TC software contain a vulnerability that could all Cisco TelePresence endpoints running either CE or TC software contain a vulnerability that could allow an authenticated, local attacker to execute a local shell command injection. More Information: CSCvb25010. Known Affected Releases: 8.1.x. Known Fixed Releases: 6.3.4 7.3.7 8.2.2 8.3.0.
nvd
CVE-2014-2172P4MEDIUMCVSS 6.6v4.0.0v4.0.1+19 more2014-05-02
CVE-2014-2172 [MEDIUM] CWE-119 CVE-2014-2172: Buffer overflow in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows loc Buffer overflow in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows local users to gain privileges by leveraging improper handling of the u-boot compiler flag for internal executable files, aka Bug ID CSCub67693.
nvd
CVE-2015-0696P4MEDIUMCVSS 4.3v6.0.0v6.0.0-cucm+12 more2015-04-15
CVE-2015-0696 [MEDIUM] CWE-79 CVE-2015-0696: Cross-site scripting (XSS) vulnerability in the login page in Cisco TC Software before 7.1.0 on Cisc Cross-site scripting (XSS) vulnerability in the login page in Cisco TC Software before 7.1.0 on Cisco TelePresence Collaboration Desk and Room Endpoints devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuq94977.
nvd
Cisco Telepresence Tc Software vulnerabilities | cvebase