VendorsCiscotelepresence_video_communication_serverx8.5.1
Vulnerabilities

Cisco Telepresence Video Communication Server x8.5.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2016-1400
Cisco TelePresence Video Communications Server (VCS) X8.x before X8.7.2 allows remote attackers to cause a denial of service (service disruption) via a crafted URI in a SIP header, aka Bug ID CSCuy43258.
Published 2016-05-25 · Modified
7.5EPSS 0.018
CVE-2022-20814
Cisco Expressway Series and Cisco TelePresence VCS Improper Certificate Validation Vulnerability
Published 2024-11-15 · Analyzed
7.4EPSS 0.009
CVE-2022-20853
Cisco Expressway Series and Cisco TelePresence VCS Cross-Site Request Forgery Vulnerability
Published 2024-11-15 · Analyzed
7.4EPSS 0.006
CVE-2024-20492
Cisco Expressway Series Privilege Escalation Vulnerability
Published 2024-10-02 · Analyzed
6.7EPSS 0.006
CVE-2016-1444
The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7 and Expressway X8.1 through X8.6 mishandles certificates, which allows remote attackers to bypass authentication via an arbitrary trusted certificate, aka Bug ID CSCuz64601.
Published 2016-07-07 · Modified
6.5EPSS 0.012
CVE-2024-20400
A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by intercepting and modifying an HTTP request from a user. A successful exploit could allow the attacker to redirect the user to a malicious web page. Note: Cisco Expressway Series refers to Cisco Expressway Control (Expressway-C) devices and Cisco Expressway Edge (Expressway-E) devices.
Published 2024-07-17 · Analyzed
4.7EPSS 0.004
CVE-2015-0752
Cross-site scripting (XSS) vulnerability in Cisco TelePresence Video Communication Server (VCS) X8.5.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut27635.
Published 2015-05-29 · Modified
4.3EPSS 0.015