PT-2015-1604 · Cisco · Cisco Telepresence Tc

Publicado

2015-06-07

·

Atualizado

2017-01-04

·

CVE-2015-0770

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco TelePresence TC versions 6.x through 6.3.3 Cisco TelePresence TC versions 7.x through 7.3.2
Description The issue is related to a CRLF injection vulnerability that exists due to insufficient input validation. This allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
Recommendations For Cisco TelePresence TC versions 6.x through 6.3.3, update to version 6.3.4 or later. For Cisco TelePresence TC versions 7.x through 7.3.2, update to version 7.3.3 or later.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-10936
CVE-2015-0770

Produtos afetados

Cisco Telepresence Tc