Vulnerabilities > Cisco > Telepresence TC Software > 4.1.2

DATE CVE VULNERABILITY TITLE RISK
2017-06-08 CVE-2017-6648 Denial of Service vulnerability in Cisco TelePresence Endpoint
A vulnerability in the Session Initiation Protocol (SIP) of the Cisco TelePresence Codec (TC) and Collaboration Endpoint (CE) Software could allow an unauthenticated, remote attacker to cause a TelePresence endpoint to reload unexpectedly, resulting in a denial of service (DoS) condition.
network
low complexity
cisco
7.8
2015-05-25 CVE-2015-0722 Resource Management Errors vulnerability in Cisco Telepresence TC Software and Telepresence TE Software
The network drivers in Cisco TelePresence T, Cisco TelePresence TE, and Cisco TelePresence TC before 7.3.2 allow remote attackers to cause a denial of service (process restart or device reload) via a flood of crafted IP packets, aka Bug ID CSCuj68952.
network
low complexity
cisco CWE-399
7.8
2015-05-25 CVE-2014-2174 Improper Access Control vulnerability in Cisco Telepresence TC Software and Telepresence TE Software
Cisco TelePresence T, TelePresence TE, and TelePresence TC before 7.1 do not properly implement access control, which allows remote attackers to obtain root privileges by sending packets on the local network and allows physically proximate attackers to obtain root privileges via unspecified vectors, aka Bug ID CSCub67651.
low complexity
cisco CWE-284
8.3
2014-05-02 CVE-2014-2175 Improper Input Validation vulnerability in Cisco Telepresence TC Software and Telepresence TE Software
Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allow remote attackers to cause a denial of service (memory consumption) via crafted H.225 packets, aka Bug ID CSCtq78849.
network
low complexity
cisco CWE-20
7.8
2014-05-02 CVE-2014-2173 Permissions, Privileges, and Access Controls vulnerability in Cisco Telepresence TC Software and Telepresence TE Software
Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 do not properly restrict access to the serial port, which allows local users to gain privileges via unspecified commands, aka Bug ID CSCub67692.
local
low complexity
cisco CWE-264
7.2
2014-05-02 CVE-2014-2172 Buffer Errors vulnerability in Cisco Telepresence TC Software and Telepresence TE Software
Buffer overflow in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows local users to gain privileges by leveraging improper handling of the u-boot compiler flag for internal executable files, aka Bug ID CSCub67693.
local
cisco CWE-119
6.6
2014-05-02 CVE-2014-2171 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cisco Telepresence TC Software and Telepresence TE Software
Heap-based buffer overflow in Cisco TelePresence TC Software 4.x through 6.x before 6.0.1 and TE Software 4.x and 6.0.x before 6.0.2 allows remote attackers to execute arbitrary code via crafted SIP packets, aka Bug ID CSCud81796.
network
low complexity
cisco CWE-119
critical
10.0
2014-05-02 CVE-2014-2170 Code Injection vulnerability in Cisco Telepresence TC Software and Telepresence TE Software
Cisco TelePresence TC Software 4.x and 5.x before 5.1.7 and 6.x before 6.0.1 and TE Software 4.x and 6.0 allow remote authenticated users to execute arbitrary commands by using the commands as arguments to tshell (aka tcsh) scripts, aka Bug ID CSCue60202.
network
low complexity
cisco CWE-94
critical
9.0
2014-05-02 CVE-2014-2169 Improper Input Validation vulnerability in Cisco Telepresence TC Software and Telepresence TE Software
Cisco TelePresence TC Software 4.x through 6.x before 6.2.0 and TE Software 4.x and 6.0 allow remote authenticated users to execute arbitrary commands by using the commands as arguments to internal system scripts, aka Bug ID CSCue60211.
network
low complexity
cisco CWE-20
critical
9.0
2014-05-02 CVE-2014-2168 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cisco Telepresence TC Software and Telepresence TE Software
Buffer overflow in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows remote attackers to execute arbitrary code via crafted DNS response packets, aka Bug ID CSCty44804.
network
high complexity
cisco CWE-119
7.6