Hosted Collaboration Solution
Vendor:
First CVE: Apr 5, 2013 · Active for 13 years
15
Total CVEs
More Total CVEs than 92% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 18% of tracked products
6.7%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Hosted Collaboration Solution over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 5, 2013
13 years ago
Most Recent CVE
Nov 26, 2019
2,432 days ago
CVE Severity & Scoring
Hosted Collaboration Solution15 CVEs
80%
13%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (6.7%)
Network4 (26.7%)
Unknown10 (66.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (26.7%)
High1 (6.7%)
Unknown10 (66.7%)
User Interaction
None3 (20.0%)
Unknown10 (66.7%)
Required2 (13.3%)
Privileges Required
Low2 (13.3%)
High0 (0.0%)
None3 (20.0%)
Unknown10 (66.7%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9805HIGH The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type f | Sep 15, 2017 | 8.1 | 99 | YES | YES |
CVE-2017-12337CRITICAL A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platform could allow an unauthenticated, remote attacker | Nov 16, 2017 | 9.8 | 33 | NO | NO |
CVE-2019-1911HIGH A vulnerability in the CLI of Cisco Unified Communications Domain Manager (Cisco Unified CDM) Software could allow an authenticated, local attacker to escape the restricted shell. | Jul 6, 2019 | 7.8 | 25 | NO | NO |
CVE-2018-0386MEDIUM A vulnerability in Cisco Unified Communications Domain Manager Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on an affecte | Aug 15, 2018 | 6.1 | 22 | NO | NO |
CVE-2019-15968MEDIUM A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager (Unified CDM) could allow an authenticated, remote attacker to conduct a cross- | Nov 26, 2019 | 5.4 | 18 | NO | NO |
CVE-2015-0750MEDIUM The administrative web interface in Cisco Hosted Collaboration Solution (HCS) 10.6(1) and earlier allows remote authenticated users to execute arbitrary commands via crafted input | May 23, 2015 | 6.5 | 18 | NO | NO |
CVE-2015-0741MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in Cisco Prime Central for Hosted Collaboration Solution (PC4HCS) 10.6(1) and earlier allow remote attackers to hijack th | May 21, 2015 | 6.8 | 18 | NO | NO |
CVE-2014-2121MEDIUM The Java-based software in Cisco Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of service (closing of TCP ports) via unspecified vectors, aka Bug ID | Mar 19, 2014 | 5.0 | 17 | NO | NO |
CVE-2014-2122MEDIUM Memory leak in the GUI in the Impact server in Cisco Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of service (memory consumption) via unspecified v | Mar 19, 2014 | 5.0 | 16 | NO | NO |
CVE-2013-3381MEDIUM Cisco Hosted Collaboration Mediation allows remote attackers to cause a denial of service (CPU consumption) via a flood of malformed UDP packets on port 162, aka Bug ID CSCug85756. | Jun 12, 2013 | 5.0 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
1 CVE
6.7% of CVEs· 97th percentile
Metasploit
1 CVE
6.7% of CVEs· 97th percentile
Nuclei
1 CVE
6.7% of CVEs· 97th percentile
ExploitDB
1 CVE
6.7% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For Hosted Collaboration Solution
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.5\(1\)_base | 1 | 6.5 | 1.4% | 0 | 0 |
| 9.2\(1\)_base | 1 | 6.5 | 1.4% | 0 | 0 |
| 9.1\(1\)_base | 1 | 6.5 | 1.4% | 0 | 0 |
| 9.0\(1\)_base | 1 | 6.5 | 1.4% | 0 | 0 |
| 8.6\(2\)_base | 1 | 6.5 | 1.4% | 0 | 0 |
| 8.6\(1\)_base | 1 | 6.5 | 1.4% | 0 | 0 |
| 8.1\(8\)er1 | 1 | 5.4 | 0.6% | 0 | 0 |
| 8.0\(2\)_base | 1 | 6.5 | 1.4% | 0 | 0 |
| 11.6\(1\) | 1 | 8.1 | 99.5% | 1 | 1 |
| 11.5\(1\) | 2 | 7.1 | 50.6% | 1 | 1 |
| 11.0\(1\) | 1 | 8.1 | 99.5% | 1 | 1 |
| 10.6_base | 1 | 4.3 | 1.8% | 0 | 0 |
| 10.6\(3\)_base | 1 | 4.0 | 1.0% | 0 | 0 |
| 10.6\(2\)_base | 1 | 6.5 | 1.4% | 0 | 0 |
| 10.6\(1\)_base | 1 | 4.3 | 1.6% | 0 | 0 |
| 10.5\(1\)_base | 1 | 6.5 | 1.4% | 0 | 0 |
| 10.5\(1\) | 1 | 8.1 | 99.5% | 1 | 1 |
| 10.1\(2\)_base | 1 | 6.5 | 1.4% | 0 | 0 |
| 10.1\(1\)_base | 1 | 6.5 | 1.4% | 0 | 0 |
| 10.0\(1\)_base | 1 | 6.5 | 1.4% | 0 | 0 |