CVE-2015-0696

Cisco TelePresence TC Software - Cross-Site Scripting in Login Page

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in the login page in Cisco TC Software before 7.1.0 on Cisco TelePresence Collaboration Desk and Room Endpoints devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuq94977.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory x_refsource_cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=38349
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1032137

Scores

EPSS 0.0155
EPSS Percentile 72.4%

Details

CWE
CWE-79
Status published
Products (14)
cisco/telepresence_tc_software 6.0.0
cisco/telepresence_tc_software 6.0.0-cucm
cisco/telepresence_tc_software 6.0.1
cisco/telepresence_tc_software 6.0.1-cucm
cisco/telepresence_tc_software 6.0.2
cisco/telepresence_tc_software 6.0_base
cisco/telepresence_tc_software 6.1.0
cisco/telepresence_tc_software 6.1.0-cucm
cisco/telepresence_tc_software 6.1.1
cisco/telepresence_tc_software 6.1.1-cucm
... and 4 more
Published Apr 15, 2015
Tracked Since Feb 18, 2026