PT-2015-1604 · Cisco · Cisco Telepresence Tc
Published
2015-06-07
·
Updated
2017-01-04
·
CVE-2015-0770
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco TelePresence TC versions 6.x through 6.3.3
Cisco TelePresence TC versions 7.x through 7.3.2
Description
The issue is related to a CRLF injection vulnerability that exists due to insufficient input validation. This allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
Recommendations
For Cisco TelePresence TC versions 6.x through 6.3.3, update to version 6.3.4 or later.
For Cisco TelePresence TC versions 7.x through 7.3.2, update to version 7.3.3 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Telepresence Tc