Vulnerabilities > Cisco > Telepresence Video Communication Server Software > x7.2

DATE CVE VULNERABILITY TITLE RISK
2015-03-13 CVE-2015-0653 Improper Authentication vulnerability in Cisco products
The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before X8.2.2 and Cisco TelePresence Conductor before X2.3.1 and XC2.4 before XC2.4.1 allows remote attackers to bypass authentication via crafted login parameters, aka Bug IDs CSCur02680 and CSCur05556.
network
low complexity
cisco CWE-287
critical
10.0
2015-03-13 CVE-2015-0652 Improper Input Validation vulnerability in Cisco products
The Session Description Protocol (SDP) implementation in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X8.2 and Cisco TelePresence Conductor before XC2.4 allows remote attackers to cause a denial of service (mishandled exception and device reload) via a crafted media description, aka Bug IDs CSCus96593 and CSCun73192.
network
low complexity
cisco CWE-20
7.8
2014-10-19 CVE-2014-3370 Resource Management Errors vulnerability in Cisco products
Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allow remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug IDs CSCum60442 and CSCum60447.
network
cisco CWE-399
7.1
2014-10-19 CVE-2014-3369 Resource Management Errors vulnerability in Cisco products
The SIP IX implementation in Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.1.1 allows remote attackers to cause a denial of service (device reload) via crafted SDP packets, aka Bug ID CSCuo42252.
network
cisco CWE-399
7.1
2014-10-19 CVE-2014-3368 Resource Management Errors vulnerability in Cisco products
Cisco TelePresence Video Communication Server (VCS) and Expressway Software before X8.2 allow remote attackers to cause a denial of service (device reload) via a high rate of crafted packets, aka Bug ID CSCui06507.
network
low complexity
cisco CWE-399
7.8
2014-01-22 CVE-2014-0662 Improper Input Validation vulnerability in Cisco products
The SIP module in Cisco TelePresence Video Communication Server (VCS) before 8.1 allows remote attackers to cause a denial of service (process failure) via a crafted SDP message, aka Bug ID CSCue97632.
network
cisco CWE-20
7.1