Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.107002
Kategorie:CISCO
Titel:Cisco TelePresence XML Application Programming Interface Authentication Bypass Vulnerability (cisco-sa-20160504-tpxml)
Zusammenfassung:Cisco TelePresence Codec (TC) and Collaboration Endpoint (CE) Software are vulnerable to a; vulnerability in the XML application programming interface (API) which could allow an unauthenticated, remote; attacker to bypass authentication and access a targeted system through the API
Beschreibung:Summary:
Cisco TelePresence Codec (TC) and Collaboration Endpoint (CE) Software are vulnerable to a
vulnerability in the XML application programming interface (API) which could allow an unauthenticated, remote
attacker to bypass authentication and access a targeted system through the API

Vulnerability Insight:
The vulnerability is due to improper implementation of authentication mechanisms for the XML
API of the affected software. An attacker could exploit this vulnerability by sending a crafted HTTP request to the XML API.

Vulnerability Impact:
A successful exploit could allow the attacker to perform unauthorized configuration changes
or issue control commands to the affected system by using the API.

Affected Software/OS:
This vulnerability affects Cisco TelePresence Software releases TC 7.2.0, TC 7.2.1, TC 7.3.0,
TC 7.3.1, TC 7.3.2, TC 7.3.3, TC 7.3.4, TC 7.3.5, CE 8.0.0, CE 8.0.1, and CE 8.1.0 running on the following Cisco products:

- TelePresence EX Series

- TelePresence Integrator C Series

- TelePresence MX Series

- TelePresence Profile Series

- TelePresence SX Series

- TelePresence SX Quick Set Series

- TelePresence VX Clinical Assistant

- TelePresence VX Tactical

Solution:
Update to version 7.3.6, 8.1.1 or later.

CVSS Score:
9.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2016-1387
Cisco Security Advisory: 20160504 Cisco TelePresence XML Application Programming Interface Authentication Bypass Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160504-tpxml
http://www.securitytracker.com/id/1035744
CopyrightCopyright (C) 2016 Greenbone AG

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.