Telepresence Server Software

Vendor:

First CVE: Apr 18, 2013 · Active for 13 years

7
Total CVEs
More Total CVEs than 83% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Telepresence Server Software over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 18, 2013
13 years ago
Most Recent CVE
Mar 17, 2017
3,419 days ago

CVE Severity & Scoring

Telepresence Server Software7 CVEs
All CVEs352,727 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (14.3%)
Unknown6 (85.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (14.3%)
High0 (0.0%)
Unknown6 (85.7%)
User Interaction
None1 (14.3%)
Unknown6 (85.7%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (14.3%)
Unknown6 (85.7%)

Top CVEs

Signals from CVEs in this product scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The web framework in Cisco TelePresence Advanced Media Gateway Series Software before 1.1(1.40), Cisco TelePresence IP Gateway Series Software, Cisco TelePresence IP VCR Series Sof
May 25, 20159.023NONO
Buffer overflow in the Conference Control Protocol API implementation in Cisco TelePresence Server software before 4.1(2.33) on 7010, MSE 8710, Multiparty Media 310 and 320, and Vi
Sep 20, 20157.820NONO
The DSP card on Cisco TelePresence MCU 4500 and 4501 devices before 4.3(2.30), TelePresence MCU MSE 8510 devices before 4.3(2.30), and TelePresence Server before 2.3(1.55) does not
Apr 18, 20137.119NONO
Cross-site request forgery (CSRF) vulnerability in Cisco TelePresence Server software 3.0(2.24) allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs
Sep 24, 20156.818NONO
Cisco Virtual TelePresence Server Software does not properly restrict use of the serial port, which allows local users to execute arbitrary OS commands as root by leveraging vSpher
Mar 14, 20157.218NONO
An API Privilege vulnerability in Cisco TelePresence Server Software could allow an unauthenticated, remote attacker to emulate Cisco TelePresence Server endpoints. Affected Produc
Mar 17, 20175.315NONO
Multiple cross-site scripting (XSS) vulnerabilities in the login page in the administrative web interface in Cisco TelePresence Server Software 4.0(2.8) allow remote attackers to i
Jul 26, 20144.314NONO

Exploit Exposure

Signals from CVEs in this product scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (7 CVEs).

Media Mentions

Signals from CVEs in this product scope (7 CVEs).

Top CNAs Publishing CVEs For Telepresence Server Software

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.2\(4.19\)15.31.0%00
4.2\(4.18\)15.31.0%00
4.2\(4.17\)15.31.0%00
4.1\(1.79\)17.82.4%00
4.0\(2.8\)37.02.2%00
4.0\(1.57\)37.02.2%00
3.1\(1.98\)26.01.9%00
3.1\(1.97\)17.82.4%00
3.1\(1.96\)17.82.4%00
3.1\(1.95\)17.82.4%00
3.1\(1.82\)17.82.4%00
3.1\(1.80\)17.82.4%00
3.0\(2.49\)17.82.4%00
3.0\(2.48\)17.82.4%00
3.0\(2.46\)17.82.4%00
3.0\(2.24\)47.01.9%00
2.3\(1.57\)28.42.6%00
2.3\(1.55\)28.42.6%00
2.2\(1.54\)19.02.9%00
2.2\(1.48\)19.02.9%00