VendorsCiscotelepresence_video_communication_serverx8.7
Vulnerabilities

Cisco Telepresence Video Communication Server x8.7

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2018-0409
A vulnerability in the XCP Router service of the Cisco Unified Communications Manager IM & Presence Service (CUCM IM&P) and the Cisco TelePresence Video Communication Server (VCS) and Expressway could allow an unauthenticated, remote attacker to cause a temporary service outage for all IM&P users, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a malicious IPv4 or IPv6 packet to an affected device on TCP port 7400. An exploit could allow the attacker to overread a buffer, resulting in a crash and restart of the XCP Router service. Cisco Bug IDs: CSCvg97663, CSCvi55947.
Published 2018-08-15 · Modified
7.5EPSS 0.035
CVE-2022-20814
Cisco Expressway Series and Cisco TelePresence VCS Improper Certificate Validation Vulnerability
Published 2024-11-15 · Analyzed
7.4EPSS 0.009
CVE-2022-20853
Cisco Expressway Series and Cisco TelePresence VCS Cross-Site Request Forgery Vulnerability
Published 2024-11-15 · Analyzed
7.4EPSS 0.006
CVE-2017-6790
A vulnerability in the Session Initiation Protocol (SIP) on the Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the targeted appliance. The vulnerability is due to excessive SIP traffic sent to the device. An attacker could exploit this vulnerability by transmitting large volumes of SIP traffic to the VCS. An exploit could allow the attacker to cause a complete DoS condition on the targeted system. Cisco Bug IDs: CSCve32897.
Published 2017-08-17 · Modified
7.1EPSS 0.020
CVE-2024-20492
Cisco Expressway Series Privilege Escalation Vulnerability
Published 2024-10-02 · Analyzed
6.7EPSS 0.006
CVE-2016-1444
The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7 and Expressway X8.1 through X8.6 mishandles certificates, which allows remote attackers to bypass authentication via an arbitrary trusted certificate, aka Bug ID CSCuz64601.
Published 2016-07-07 · Modified
6.5EPSS 0.012
CVE-2024-20400
A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by intercepting and modifying an HTTP request from a user. A successful exploit could allow the attacker to redirect the user to a malicious web page. Note: Cisco Expressway Series refers to Cisco Expressway Control (Expressway-C) devices and Cisco Expressway Edge (Expressway-E) devices.
Published 2024-07-17 · Analyzed
4.7EPSS 0.004