HIGH · 10.0

CVE-2015-0653

The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before X8.2.2 and Cisco TelePresence Conductor before X2....

Vulnerability Description

The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before X8.2.2 and Cisco TelePresence Conductor before X2.3.1 and XC2.4 before XC2.4.1 allows remote attackers to bypass authentication via crafted login parameters, aka Bug IDs CSCur02680 and CSCur05556.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoExpressway Software>= x7.2, < x7.2.4
CiscoTelepresence Conductor>= x2.3, < x2.3.1
CiscoTelepresence Video Communication Server Software>= x7.2, < x7.2.4

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-0653?

CVE-2015-0653 is a vulnerability with a CVSS score of 10.0 (HIGH). The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before X8.2.2 and Cisco TelePresence Conductor before X2....

How severe is CVE-2015-0653?

CVE-2015-0653 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-0653?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Expressway Software, Cisco Telepresence Conductor, Cisco Telepresence Video Communication Server Software.