Vulnerability Description
The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before X8.2.2 and Cisco TelePresence Conductor before X2.3.1 and XC2.4 before XC2.4.1 allows remote attackers to bypass authentication via crafted login parameters, aka Bug IDs CSCur02680 and CSCur05556.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Expressway Software | >= x7.2, < x7.2.4 |
| Cisco | Telepresence Conductor | >= x2.3, < x2.3.1 |
| Cisco | Telepresence Video Communication Server Software | >= x7.2, < x7.2.4 |
Related Weaknesses (CWE)
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20Vendor Advisory
- http://www.securitytracker.com/id/1031910Third Party AdvisoryVDB Entry
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20Vendor Advisory
- http://www.securitytracker.com/id/1031910Third Party AdvisoryVDB Entry
FAQ
What is CVE-2015-0653?
CVE-2015-0653 is a vulnerability with a CVSS score of 10.0 (HIGH). The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before X8.2.2 and Cisco TelePresence Conductor before X2....
How severe is CVE-2015-0653?
CVE-2015-0653 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-0653?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Expressway Software, Cisco Telepresence Conductor, Cisco Telepresence Video Communication Server Software.