cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2023-20249,https://securityvulnerability.io/vulnerability/CVE-2023-20249,Cisco TelePresence Management Suite Software Vulnerability Could Lead to Cross-Site Scripting Attacks,"A vulnerability exists in the web-based management interface of Cisco TelePresence Management Suite (TMS) Software that can be exploited by an authenticated remote attacker to perform a cross-site scripting (XSS) attack. The root cause of this vulnerability lies in the insufficient input validation implemented within the management interface. By manipulating specific data fields within the interface, an attacker could insert malicious scripts, allowing execution of arbitrary code in the context of the affected interface. This could also lead to unauthorized access to sensitive information stored in the user's browser.",Cisco,Cisco Telepresence Management Suite (tms),5.4,MEDIUM,0.0004299999854993075,false,,false,false,false,,,false,false,,2024-04-24T20:47:22.184Z,0 CVE-2023-20248,https://securityvulnerability.io/vulnerability/CVE-2023-20248,Cisco TelePresence Management Suite Software Vulnerability Could Lead to Cross-Site Scripting Attacks,"A vulnerability exists in the web-based management interface of the Cisco TelePresence Management Suite (TMS) Software, enabling authenticated, remote attackers to potentially carry out a cross-site scripting (XSS) attack. This issue arises from inadequate input validation within the management interface, which allows malicious data to be inserted into specific fields. If exploited, the attacker could execute arbitrary script code within the context of the affected interface or gain unauthorized access to sensitive information stored in the user's browser.",Cisco,Cisco Telepresence Management Suite (tms),,,0.0004299999854993075,false,,false,false,true,2024-08-29T18:15:04.000Z,,false,false,,2024-04-24T20:46:55.722Z,0 CVE-2021-34760,https://securityvulnerability.io/vulnerability/CVE-2021-34760,Cisco TelePresence Management Suite Stored Cross-Site Scripting Vulnerability,"A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability by inserting malicious data in a specific data field in the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.",Cisco,Cisco Telepresence Management Suite (tms),4.8,MEDIUM,0.0006600000197067857,false,,false,false,true,2024-08-04T02:15:23.000Z,,false,false,,2021-10-21T03:15:00.000Z,0 CVE-2020-3185,https://securityvulnerability.io/vulnerability/CVE-2020-3185,Cisco TelePresence Management Suite Stored Cross-Site Scripting Vulnerability,"A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability by inserting malicious data in a specific data field in the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected web-based management interface or access sensitive, browser-based information.",Cisco,Cisco Telepresence Management Suite (tms),4.8,MEDIUM,0.0006600000197067857,false,,false,false,true,2024-08-04T08:16:28.000Z,,false,false,,2020-03-04T00:00:00.000Z,0 CVE-2019-1661,https://securityvulnerability.io/vulnerability/CVE-2019-1661,Cisco TelePresence Management Suite Cross-Site Scripting Vulnerability,"A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information.",Cisco,Cisco Telepresence Management Suite (tms),6.1,MEDIUM,0.0007099999929778278,false,,false,false,true,2024-08-04T19:16:03.000Z,,false,false,,2019-02-07T22:29:00.000Z,0 CVE-2019-1660,https://securityvulnerability.io/vulnerability/CVE-2019-1660,Cisco TelePresence Management Suite Simple Object Access Protocol Vulnerability,"A vulnerability in the Simple Object Access Protocol (SOAP) of Cisco TelePresence Management Suite (TMS) software could allow an unauthenticated, remote attacker to gain unauthorized access to an affected device. The vulnerability is due to a lack of proper access and authentication controls on the affected TMS software. An attacker could exploit this vulnerability by gaining access to internal, trusted networks to send crafted SOAP calls to the affected device. If successful, an exploit could allow the attacker to access system management tools. Under normal circumstances, this access should be prohibited.",Cisco,Cisco Telepresence Management Suite (tms),5.3,MEDIUM,0.0010300000431016088,false,,false,false,true,2024-08-04T19:16:03.000Z,,false,false,,2019-02-07T21:29:00.000Z,0 CVE-2018-15467,https://securityvulnerability.io/vulnerability/CVE-2018-15467,Cisco TelePresence Management Suite Cross-Site Scripting Vulnerability,"A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information.",Cisco,Cisco Telepresence Management Suite (tms),6.1,MEDIUM,0.0007099999929778278,false,,false,false,true,2024-08-05T10:17:54.000Z,,false,false,,2019-01-11T15:29:00.000Z,0 CVE-2018-0409,https://securityvulnerability.io/vulnerability/CVE-2018-0409,,"A vulnerability in the XCP Router service of the Cisco Unified Communications Manager IM & Presence Service (CUCM IM&P) and the Cisco TelePresence Video Communication Server (VCS) and Expressway could allow an unauthenticated, remote attacker to cause a temporary service outage for all IM&P users, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a malicious IPv4 or IPv6 packet to an affected device on TCP port 7400. An exploit could allow the attacker to overread a buffer, resulting in a crash and restart of the XCP Router service. Cisco Bug IDs: CSCvg97663, CSCvi55947.",Cisco,"Unified Communications Manager Im & Presence Service (cucm Im&p),Telepresence Video Communication Server (vcs) And Expressway",7.5,HIGH,0.008550000376999378,false,,false,false,false,,,false,false,,2018-08-15T00:00:00.000Z,0 CVE-2015-0620,https://securityvulnerability.io/vulnerability/CVE-2015-0620,,"The XML parser in Cisco TelePresence Management Suite (TMS) 14.3(.2) and earlier does not properly handle external entities, which allows remote authenticated users to cause a denial of service via POST requests, aka Bug ID CSCus51494.",Cisco,Telepresence Management Suite,,,0.004470000043511391,false,,false,false,false,,,false,false,,2015-02-18T02:00:00.000Z,0 CVE-2013-1229,https://securityvulnerability.io/vulnerability/CVE-2013-1229,,"TMSSNMPService.exe in TelePresence Manager in Cisco TelePresence Management Suite (TMS) on 64-bit platforms allows remote attackers to cause a denial of service (process crash) via SNMP traps, aka Bug ID CSCue00028.",Cisco,Telepresence Management Suite,,,0.001610000035725534,false,,false,false,false,,,false,false,,2013-05-01T12:00:00.000Z,0 CVE-2011-0380,https://securityvulnerability.io/vulnerability/CVE-2011-0380,,"Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to bypass authentication and invoke arbitrary methods via a malformed SOAP request, aka Bug ID CSCtc59562.",Cisco,Telepresence Manager,,,0.008200000040233135,false,,false,false,false,,,false,false,,2011-02-25T11:00:00.000Z,0 CVE-2011-0381,https://securityvulnerability.io/vulnerability/CVE-2011-0381,,"Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to perform unspecified actions and consequently execute arbitrary code via a crafted request to the Java RMI interface, related to a ""command injection vulnerability,"" aka Bug ID CSCtf97085.",Cisco,Telepresence Manager,,,0.016659999266266823,false,,false,false,false,,,false,false,,2011-02-25T11:00:00.000Z,0 CVE-2010-3036,https://securityvulnerability.io/vulnerability/CVE-2010-3036,,"Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary code via a session on TCP port (1) 443 or (2) 1741, aka Bug ID CSCti41352.",Cisco,"Ciscoworks Common Services,Ciscoworks Lan Management Solution,Qos Policy Manager,Security Manager,Telepresence Readiness Assessment Manager,Unified Operations Manager,Unified Service Monitor",,,0.07632999867200851,false,,false,false,false,,,false,false,,2010-10-29T18:00:00.000Z,0 CVE-2009-1161,https://securityvulnerability.io/vulnerability/CVE-2009-1161,,"Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, as used in Cisco Unified Service Monitor, Security Manager, TelePresence Readiness Assessment Manager, Unified Operations Manager, Unified Provisioning Manager, and other products, allows remote attackers to access arbitrary files via unspecified vectors.",Cisco,"Ciscoworks Common Services,Ciscoworks Health And Utilization Monitor,Ciscoworks Lan Management Solution,Ciscoworks Qos Policy Manager,Ciscoworks Voice Manager,Security Manager,Telepresence Readiness Assessment Manager,Unified Operations Manager,Unified Provisioning Manager,Unified Service Monitor",,,0.018859999254345894,false,,false,false,false,,,false,false,,2009-05-21T14:00:00.000Z,0