Cisco Telepresence Video Communication Server vulnerabilities
36 known vulnerabilities affecting cisco/telepresence_video_communication_server.
Total CVEs
36
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH18MEDIUM18
Vulnerabilities
Page 1 of 2
CVE-2023-44487P1HIGHCVSS 7.5KEVPoCfixed in x14.3.32023-10-10
CVE-2023-44487 [HIGH] CWE-400 CVE-2023-44487: The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancell
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
nvd
CVE-2023-20209P2HIGHCVSS 7.2fixed in 14.3.12023-08-16
CVE-2023-20209 [HIGH] CWE-94 CVE-2023-20209: A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePrese
A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read-write privileges on the application to perform a command injection attack that could result in remote code execution on an affected device.
This vulnerability is
nvd
CVE-2016-1468P3HIGHCVSS 8.8vx8.5.22016-08-08
CVE-2016-1468 [HIGH] CWE-78 CVE-2016-1468: The administrative web interface in Cisco TelePresence Video Communication Server Expressway X8.5.2
The administrative web interface in Cisco TelePresence Video Communication Server Expressway X8.5.2 allows remote authenticated users to execute arbitrary commands via crafted fields, aka Bug ID CSCuv12531.
nvd
CVE-2022-20755P3HIGHCVSS 7.2fixed in 14.0.52022-04-06
CVE-2022-20755 [HIGH] CWE-23 CVE-2022-20755: Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series a
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read/write privileges to the application to write files or execute arbitrary code on the underlying operating system of an affected device as the ro
nvd
CVE-2022-20754P3HIGHCVSS 7.2fixed in 14.0.52022-04-06
CVE-2022-20754 [HIGH] CWE-23 CVE-2022-20754: Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series a
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read/write privileges to the application to write files or execute arbitrary code on the underlying operating system of an affected device as the ro
nvd
CVE-2019-1845P3HIGHCVSS 8.6≥ x8.1, ≤ x12.5.22019-06-05
CVE-2019-1845 [HIGH] CWE-20 CVE-2019-1845: A vulnerability in the authentication service of the Cisco Unified Communications Manager IM and Pre
A vulnerability in the authentication service of the Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, Cisco TelePresence Video Communication Server (VCS), and Cisco Expressway Series could allow an unauthenticated, remote attacker to cause a service outage for users attempting to authenticate, resulting in a denial of servi
nvd
CVE-2022-20814P3HIGHCVSS 7.4vx8.1vx8.1.1+58 more2024-11-15
CVE-2022-20814 [HIGH] CWE-295 CVE-2022-20814: A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence
A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability is due to a lack of validation of the SSL server certificate that an affected device receives when it establishes a connection to a Cisco Unified
nvd
CVE-2021-34716P3HIGHCVSS 7.2≥ x8.6, ≤ x14.0.32021-08-18
CVE-2021-34716 [HIGH] CWE-460 CVE-2021-34716: A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePrese
A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as the root user. This vulnerability is due to incorrect handling of certain crafted software images that are
nvd
CVE-2017-3790P3HIGHCVSS 8.6vx5.2_basevx6.0_base+9 more2017-02-01
CVE-2017-3790 [HIGH] CWE-399 CVE-2017-3790: A vulnerability in the received packet parser of Cisco Expressway Series and Cisco TelePresence Vide
A vulnerability in the received packet parser of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) software could allow an unauthenticated, remote attacker to cause a reload of the affected system, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient size validation of user-supplied dat
nvd
CVE-2023-20192P3HIGHCVSS 7.7≤ x14.0.32023-06-28
CVE-2023-20192 [HIGH] CWE-20 CVE-2023-20192: Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Serve
Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated attacker with Administrator-level read-only credentials to elevate their privileges to Administrator with read-write credentials on an affected system. Note: "Cisco Expressway Series" refers to Cisco Expressway Contro
nvd
CVE-2018-15430P3HIGHCVSS 7.2vx7.2.4vx8.9.2+1 more2018-10-05
CVE-2018-15430 [HIGH] CWE-20 CVE-2018-15430: A vulnerability in the administrative web interface of Cisco Expressway Series and Cisco TelePresenc
A vulnerability in the administrative web interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with user-level privileges on the underlying operating system. The vulnerability is due to insufficient validation of the content of upgrade packages. An att
nvd
CVE-2011-2538P3HIGHCVSS 7.2fixed in x7.0.32019-10-29
CVE-2011-2538 [HIGH] CWE-74 CVE-2011-2538: Cisco Video Communications Server (VCS) before X7.0.3 contains a command injection vulnerability whi
Cisco Video Communications Server (VCS) before X7.0.3 contains a command injection vulnerability which allows remote, authenticated attackers to execute arbitrary commands.
nvd
CVE-2018-0409P3HIGHCVSS 7.5vx7.0.1vx7.2.4+9 more2018-08-15
CVE-2018-0409 [HIGH] CWE-20 CVE-2018-0409: A vulnerability in the XCP Router service of the Cisco Unified Communications Manager IM & Presence
A vulnerability in the XCP Router service of the Cisco Unified Communications Manager IM & Presence Service (CUCM IM&P) and the Cisco TelePresence Video Communication Server (VCS) and Expressway could allow an unauthenticated, remote attacker to cause a temporary service outage for all IM&P users, resulting in a denial of service (DoS) condition. The vuln
nvd
CVE-2021-34715P3HIGHCVSS 7.2≤ x8.82021-08-18
CVE-2021-34715 [HIGH] CWE-347 CVE-2021-34715: A vulnerability in the image verification function of Cisco Expressway Series and Cisco TelePresence
A vulnerability in the image verification function of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with internal user privileges on the underlying operating system. The vulnerability is due to insufficient validation of the content of upgrade packages. An
nvd
CVE-2022-20812P3MEDIUMCVSS 6.5fixed in x14.0.72022-07-06
CVE-2022-20812 [MEDIUM] CWE-158 CVE-2022-20812: Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Se
Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected device. Note: Cisco Expressway Series refers to the Expressway Control (Expre
nvd
CVE-2016-1444P3MEDIUMCVSS 6.5vx8.1vx8.1.1+12 more2016-07-07
CVE-2016-1444 [MEDIUM] CWE-20 CVE-2016-1444: The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS)
The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7 and Expressway X8.1 through X8.6 mishandles certificates, which allows remote attackers to bypass authentication via an arbitrary trusted certificate, aka Bug ID CSCuz64601.
nvd
CVE-2022-20853P3HIGHCVSS 7.4vx8.1vx8.1.1+57 more2024-11-15
CVE-2022-20853 [HIGH] CWE-352 CVE-2022-20853: A vulnerability in the REST API of Cisco Expressway Series and Cisco TelePresence VCS coul
A vulnerability in the REST API of Cisco Expressway Series and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system.
This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected system. An attacker could ex
nvd
CVE-2023-20105P3MEDIUMCVSS 6.5≤ x14.0.32023-06-28
CVE-2023-20105 [MEDIUM] CWE-20 CVE-2023-20105: A vulnerability in the change password functionality of Cisco Expressway Series and Cisco TelePresen
A vulnerability in the change password functionality of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with Read-only credentials to elevate privileges to Administrator on an affected system.
This vulnerability is due to incorrect handling of password change requests. An a
nvd
CVE-2020-3596P3HIGHCVSS 7.5≤ x12.6.32020-10-08
CVE-2020-3596 [HIGH] CWE-789 CVE-2020-3596: A vulnerability in the Session Initiation Protocol (SIP) of Cisco Expressway Series and Cisco TelePr
A vulnerability in the Session Initiation Protocol (SIP) of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect handling of incoming SIP traffic. An attacker could exploit t
nvd
CVE-2020-3482P3MEDIUMCVSS 6.5fixed in x12.6.32020-11-18
CVE-2020-3482 [MEDIUM] CWE-284 CVE-2020-3482: A vulnerability in the Traversal Using Relays around NAT (TURN) server component of Cisco Expressway
A vulnerability in the Traversal Using Relays around NAT (TURN) server component of Cisco Expressway software could allow an unauthenticated, remote attacker to bypass security controls and send network traffic to restricted destinations. The vulnerability is due to improper validation of specific connection information by the TURN server within the a
nvd
1 / 2Next →