VendorsCiscotelepresence_video_communication_serverany version
Vulnerabilities

Cisco Telepresence Video Communication Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

32CVEs
CVE-2023-20105
A vulnerability in the change password functionality of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with Read-only credentials to elevate privileges to Administrator on an affected system. This vulnerability is due to incorrect handling of password change requests. An attacker could exploit this vulnerability by authenticating to the application as a Read-only user and sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to alter the passwords of any user on the system, including an administrative user, and then impersonate that user. Note: Cisco Expressway Series refers to the Expressway Control (Expressway-C) device and the Expressway Edge (Expressway-E) device.
Published 2023-06-28 · Modified
9.6EPSS 0.009
CVE-2023-20192
Cisco Expressway Series and Cisco TelePresence Video Communication Server Privilege Escalation Vulnerabilities
Published 2023-06-28 · Modified
9.6EPSS 0.007
CVE-2022-20755
Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities
Published 2022-04-06 · Modified
9.0EPSS 0.033
CVE-2022-20754
Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities
Published 2022-04-06 · Modified
9.0EPSS 0.033
CVE-2011-2538
Cisco Video Communications Server (VCS) before X7.0.3 contains a command injection vulnerability which allows remote, authenticated attackers to execute arbitrary commands.
Published 2019-10-28 · Modified
9.0EPSS 0.026
CVE-2021-34716
Cisco Expressway Series and TelePresence Video Communication Server Remote Code Execution Vulnerability
Published 2021-08-18 · Modified
9.0EPSS 0.024
CVE-2022-20812
Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities
Published 2022-07-06 · Modified
9.0EPSS 0.019
CVE-2022-20813
Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities
Published 2022-07-06 · Modified
9.0EPSS 0.011
CVE-2021-34715
Cisco Expressway Series and TelePresence Video Communication Server Image Verification Vulnerability
Published 2021-08-18 · Modified
9.0EPSS 0.011
CVE-2019-1845
Cisco Unified Communications Manager IM&P Service, Cisco TelePresence VCS, and Cisco Expressway Series Denial of Service Vulnerability
Published 2019-06-05 · Modified
8.6EPSS 0.046
CVE-2018-5390
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service
Published 2018-08-06 · Modified
7.8EPSS 0.737
CVE-2012-0330
Cisco TelePresence Video Communication Server with software before X7.0.1 allows remote attackers to cause a denial of service (device crash) via a malformed SIP message, aka Bug ID CSCtr20426.
Published 2012-03-01 · Modified
7.8EPSS 0.013
CVE-2020-3596
Cisco Expressway Series and TelePresence Video Communication Server Denial of Service Vulnerability
Published 2020-10-08 · Modified
7.8EPSS 0.012
CVE-2019-1721
Cisco Expressway Series and Cisco TelePresence Video Communication Server Denial of Service Vulnerability
Published 2019-04-18 · Modified
7.7EPSS 0.020
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2018-0358
A vulnerability in the file descriptor handling of Cisco TelePresence Video Communication Server (VCS) Expressway could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to exhaustion of file descriptors while processing a high volume of traffic. An attacker could exploit this vulnerability by establishing a high number of concurrent TCP connections to the vulnerable system. An exploit could allow the attacker to cause a restart in a specific process, resulting in a temporary interruption of service. Cisco Bug IDs: CSCvh77056, CSCvh77058, CSCvh95264.
Published 2018-06-21 · Modified
7.5EPSS 0.024
CVE-2016-1400
Cisco TelePresence Video Communications Server (VCS) X8.x before X8.7.2 allows remote attackers to cause a denial of service (service disruption) via a crafted URI in a SIP header, aka Bug ID CSCuy43258.
Published 2016-05-25 · Modified
7.5EPSS 0.018
CVE-2012-0331
Cisco TelePresence Video Communication Server with software before X7.0.1 allows remote attackers to cause a denial of service (device crash) via a crafted SIP packet, as demonstrated by a SIP INVITE message from a Tandberg device, aka Bug ID CSCtq73319.
Published 2012-03-01 · Modified
7.5EPSS 0.013
CVE-2023-20209
A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read-write privileges on the application to perform a command injection attack that could result in remote code execution on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to establish a remote shell with root privileges.
Published 2023-08-16 · Modified
7.2EPSS 0.408
CVE-2022-20806
Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities
Published 2022-05-27 · Modified
7.1EPSS 0.010
CVE-2019-1720
Cisco Expressway Series and Cisco TelePresence Video Communication Server Denial of Service Vulnerability
Published 2019-04-18 · Modified
6.8EPSS 0.017
CVE-2020-3482
Cisco Expressway Software Unauthorized Access Information Disclosure Vulnerability
Published 2020-11-18 · Modified
6.5EPSS 0.014
CVE-2022-20807
Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities
Published 2022-05-27 · Modified
6.5EPSS 0.010
CVE-2022-20809
Cisco Expressway Series and Cisco TelePresence Video Communication Server Vulnerabilities
Published 2022-05-26 · Modified
6.5EPSS 0.010
CVE-2019-1722
Cisco Expressway Series and Cisco TelePresence Video Communication Server Cross-Site Request Forgery Vulnerability
Published 2019-04-18 · Modified
6.5EPSS 0.007
CVE-2014-0675
The Expressway component in Cisco TelePresence Video Communication Server (VCS) uses the same default X.509 certificate across different customers' installations, which makes it easier for remote attackers to conduct man-in-the-middle attacks against SSL sessions by leveraging the certificate's trust relationship, aka Bug ID CSCue07471.
Published 2014-01-23 · Modified
6.4EPSS 0.016
CVE-2019-12705
Cisco Expressway Series and TelePresence Video Communication Server Cross-Site Scripting Vulnerability
Published 2019-10-16 · Modified
6.1EPSS 0.008
CVE-2019-1872
Cisco TelePresence Video Communication Server and Cisco Expressway Series Server-Side Request Forgery Vulnerability
Published 2019-06-05 · Modified
5.3EPSS 0.015
CVE-2019-1679
Cisco TelePresence Conductor, Cisco Expressway Series, and Cisco TelePresence Video Communication Server REST API Server-Side Request Forgery Vulnerability
Published 2019-02-07 · Modified
5.0EPSS 0.021
CVE-2015-0579
Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway allow remote attackers to cause a denial of service (memory and CPU consumption, and partial outage) via crafted SIP packets, aka Bug ID CSCur12473.
Published 2015-01-14 · Modified
5.0EPSS 0.020
CVE-2012-5444
Cisco TelePresence Video Communication Server (VCS) X7.0.3 does not properly process certain search rules, which allows remote attackers to create conferences via an unspecified Conductor request, aka Bug ID CSCub67989.
Published 2013-01-17 · Modified
5.0EPSS 0.010
CVE-2017-12287
A vulnerability in the cluster database (CDB) management component of Cisco Expressway Series Software and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to cause the CDB process on an affected system to restart unexpectedly, resulting in a temporary denial of service (DoS) condition. The vulnerability is due to incomplete input validation of URL requests by the REST API of the affected software. An attacker could exploit this vulnerability by sending a crafted URL to the REST API of the affected software on an affected system. A successful exploit could allow the attacker to cause the CDB process on the affected system to restart unexpectedly, resulting in a temporary DoS condition. Cisco Bug IDs: CSCve77571.
Published 2017-10-19 · Modified
4.3EPSS 0.016