PT-2015-1604 · Cisco · Cisco Telepresence Tc

Published

2015-06-07

·

Updated

2017-01-04

·

CVE-2015-0770

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco TelePresence TC versions 6.x through 6.3.3 Cisco TelePresence TC versions 7.x through 7.3.2
Description The issue is related to a CRLF injection vulnerability that exists due to insufficient input validation. This allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
Recommendations For Cisco TelePresence TC versions 6.x through 6.3.3, update to version 6.3.4 or later. For Cisco TelePresence TC versions 7.x through 7.3.2, update to version 7.3.3 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-10936
CVE-2015-0770

Affected Products

Cisco Telepresence Tc