CVE-2015-0653 - CVE House
Back to Database
Status published Critical CVE-2015-0653

The management interface in Cisco TelePresence Video Communication Server (VCS)...

Vulnerability Description

The management interface in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway before X7.2.4, X8 before X8.1.2, and X8.2 before X8.2.2 and Cisco TelePresence Conductor before X2.3.1 and XC2.4 before XC2.4.1 allows remote attackers to bypass authentication via crafted login parameters, aka Bug IDs CSCur02680 and CSCur05556.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-0653

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

expressway software, telepresence conductor, telepresence video communication server software
Vulnerable Versions:
x7.2, x8.1, x8.2, x2.3, xc2.4

Timeline

Official Publish: March 13th, 2015
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.