// For flags

CVE-2015-0653

 

Severity Score

10.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before X8.2.2 and Cisco TelePresence Conductor before X2.3.1 and XC2.4 before XC2.4.1 allows remote attackers to bypass authentication via crafted login parameters, aka Bug IDs CSCur02680 and CSCur05556.

La interfaz de gestión en Cisco TelePresence Video Communication Server (VCS) y Cisco Expressway anterior a X7.2.4, X8 anterior a X8.1.2, y X8.2 anterior a X8.2.2 y Cisco TelePresence Conductor anterior a X2.3.1 y XC2.4 anterior a XC2.4.1 permite a atacantes remotos evadir la autenticación a través de parámetros de inicio de sesión manipulados, también conocido como Bug IDs CSCur02680 y CSCur05556.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-01-07 CVE Reserved
  • 2015-03-13 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-287: Improper Authentication
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Expressway Software
Search vendor "Cisco" for product "Expressway Software"
>= x7.2 < x7.2.4
Search vendor "Cisco" for product "Expressway Software" and version " >= x7.2 < x7.2.4"
-
Affected
Cisco
Search vendor "Cisco"
Expressway Software
Search vendor "Cisco" for product "Expressway Software"
>= x8.1 < x8.1.2
Search vendor "Cisco" for product "Expressway Software" and version " >= x8.1 < x8.1.2"
-
Affected
Cisco
Search vendor "Cisco"
Expressway Software
Search vendor "Cisco" for product "Expressway Software"
>= x8.2 < x8.2.2
Search vendor "Cisco" for product "Expressway Software" and version " >= x8.2 < x8.2.2"
-
Affected
Cisco
Search vendor "Cisco"
Telepresence Conductor
Search vendor "Cisco" for product "Telepresence Conductor"
>= x2.3 < x2.3.1
Search vendor "Cisco" for product "Telepresence Conductor" and version " >= x2.3 < x2.3.1"
-
Affected
Cisco
Search vendor "Cisco"
Telepresence Conductor
Search vendor "Cisco" for product "Telepresence Conductor"
>= xc2.4 < xc2.4.1
Search vendor "Cisco" for product "Telepresence Conductor" and version " >= xc2.4 < xc2.4.1"
-
Affected
Cisco
Search vendor "Cisco"
Telepresence Video Communication Server Software
Search vendor "Cisco" for product "Telepresence Video Communication Server Software"
>= x7.2 < x7.2.4
Search vendor "Cisco" for product "Telepresence Video Communication Server Software" and version " >= x7.2 < x7.2.4"
-
Affected
Cisco
Search vendor "Cisco"
Telepresence Video Communication Server Software
Search vendor "Cisco" for product "Telepresence Video Communication Server Software"
>= x8.1 < x8.1.2
Search vendor "Cisco" for product "Telepresence Video Communication Server Software" and version " >= x8.1 < x8.1.2"
-
Affected
Cisco
Search vendor "Cisco"
Telepresence Video Communication Server Software
Search vendor "Cisco" for product "Telepresence Video Communication Server Software"
>= x8.2 < x8.2.2
Search vendor "Cisco" for product "Telepresence Video Communication Server Software" and version " >= x8.2 < x8.2.2"
-
Affected