Vsecurity's vulnerability profile concentrates in the Tandberg Video Communication Server product, a video-conferencing and collaboration appliance with a modest disclosure history centered on information exposure, code injection, and cross-site scripting weaknesses typical of web-facing communication platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vsecurity over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-4509HIGH The administrative web console on the TANDBERG Video Communication Server (VCS) before X4.3 uses predictable session cookies in (1) tandberg/web/lib/secure.php and (2) tandberg/web | Apr 13, 2010 | 10.0 | 30 | NO | NO |
CVE-2010-1356HIGH Unspecified vulnerability on the TANDBERG Video Communication Server (VCS) before X5.0 allows remote attackers to execute arbitrary code via unknown vectors, aka Reference ID 69773 | Apr 13, 2010 | 10.0 | 25 | NO | NO |
CVE-2009-4510HIGH The SSH service on the TANDBERG Video Communication Server (VCS) before X5.1 uses a fixed DSA key, which makes it easier for remote attackers to conduct man-in-the-middle attacks a | Apr 13, 2010 | 8.5 | 25 | NO | NO |
CVE-2009-4511MEDIUM Multiple directory traversal vulnerabilities in the web administration interface on the TANDBERG Video Communication Server (VCS) before X5.1 allow remote authenticated users to re | Apr 13, 2010 | 4.0 | 24 | NO | YES |
CVE-2010-1355MEDIUM Cross-site scripting (XSS) vulnerability on the TANDBERG Video Communication Server (VCS) before X5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified | Apr 13, 2010 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vsecurity.
Media articles that mention a CVE ID that affects a product developed by Vsecurity — matched by CVE ID, not by vendor name.