Vulnerabilities > Cisco > Telepresence Video Communication Server > High

DATE CVE VULNERABILITY TITLE RISK
2023-10-10 CVE-2023-44487 The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. 7.5
2023-08-16 CVE-2023-20209 Command Injection vulnerability in Cisco Telepresence Video Communication Server 14.0/14.0.5/14.0.7
A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read-write privileges on the application to perform a command injection attack that could result in remote code execution on an affected device. This vulnerability is due to insufficient validation of user-supplied input.
network
low complexity
cisco CWE-77
7.2
2023-06-28 CVE-2023-20192 Unspecified vulnerability in Cisco Telepresence Video Communication Server
Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated attacker with Administrator-level read-only credentials to elevate their privileges to Administrator with read-write credentials on an affected system.
network
low complexity
cisco
7.7
2022-05-27 CVE-2022-20806 Information Exposure Through Log Files vulnerability in Cisco Telepresence Video Communication Server
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to write files or disclose sensitive information on an affected device.
network
low complexity
cisco CWE-532
7.1
2022-04-06 CVE-2022-20754 Unspecified vulnerability in Cisco Telepresence Video Communication Server
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read/write privileges to the application to write files or execute arbitrary code on the underlying operating system of an affected device as the root user.
network
low complexity
cisco
7.2
2022-04-06 CVE-2022-20755 Unspecified vulnerability in Cisco Telepresence Video Communication Server
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read/write privileges to the application to write files or execute arbitrary code on the underlying operating system of an affected device as the root user.
network
low complexity
cisco
7.2
2021-08-18 CVE-2021-34715 Improper Verification of Cryptographic Signature vulnerability in Cisco Telepresence Video Communication Server
A vulnerability in the image verification function of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with internal user privileges on the underlying operating system.
network
low complexity
cisco CWE-347
7.2
2021-08-18 CVE-2021-34716 Improper Handling of Exceptional Conditions vulnerability in Cisco Telepresence Video Communication Server
A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as the root user.
network
low complexity
cisco CWE-755
7.2
2020-10-08 CVE-2020-3596 Always-Incorrect Control Flow Implementation vulnerability in Cisco products
A vulnerability in the Session Initiation Protocol (SIP) of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-670
7.5
2019-10-29 CVE-2011-2538 Injection vulnerability in Cisco Telepresence Video Communication Server
Cisco Video Communications Server (VCS) before X7.0.3 contains a command injection vulnerability which allows remote, authenticated attackers to execute arbitrary commands.
network
low complexity
cisco CWE-74
7.2