cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2017-3792,https://securityvulnerability.io/vulnerability/CVE-2017-3792,,"A vulnerability in a proprietary device driver in the kernel of Cisco TelePresence Multipoint Control Unit (MCU) Software could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. The vulnerability is due to improper size validation when reassembling fragmented IPv4 or IPv6 packets. An attacker could exploit this vulnerability by sending crafted IPv4 or IPv6 fragments to a port receiving content in Passthrough content mode. An exploit could allow the attacker to overflow a buffer. If successful, the attacker could execute arbitrary code or cause a DoS condition on the affected system. Cisco TelePresence MCU platforms TelePresence MCU 5300 Series, TelePresence MCU MSE 8510 and TelePresence MCU 4500 are affected when running software version 4.3(1.68) or later configured for Passthrough content mode. Cisco has released software updates that address this vulnerability. Workarounds that address this vulnerability are not available, but mitigations are available. Cisco Bug IDs: CSCuu67675.",Cisco,Cisco Telepresence Multipoint Control Unit (mcu) Software Version 4.3(1.68) Or Later Configured For Passthrough Content Mode,9.8,CRITICAL,0.02369000017642975,false,,false,false,false,,,false,false,,2017-02-01T19:00:00.000Z,0 CVE-2015-4257,https://securityvulnerability.io/vulnerability/CVE-2015-4257,,"Cross-site request forgery (CSRF) vulnerability on Cisco TelePresence MCU 4500 devices with software 4.5(1.55) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu90710.",Cisco,Telepresence Mcu Software,,,0.001120000029914081,false,,false,false,false,,,false,false,,2015-07-10T00:00:00.000Z,0 CVE-2015-0713,https://securityvulnerability.io/vulnerability/CVE-2015-0713,,"The web framework in Cisco TelePresence Advanced Media Gateway Series Software before 1.1(1.40), Cisco TelePresence IP Gateway Series Software, Cisco TelePresence IP VCR Series Software before 3.0(1.27), Cisco TelePresence ISDN Gateway Software before 2.2(1.94), Cisco TelePresence MCU Software before 4.4(3.54) and 4.5 before 4.5(1.45), Cisco TelePresence MSE Supervisor Software before 2.3(1.38), Cisco TelePresence Serial Gateway Series Software before 1.0(1.42), Cisco TelePresence Server Software for Hardware before 3.1(1.98), and Cisco TelePresence Server Software for Virtual Machine before 4.1(1.79) allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors, aka Bug IDs CSCul55968, CSCur08993, CSCur15803, CSCur15807, CSCur15825, CSCur15832, CSCur15842, CSCur15850, and CSCur15855.",Cisco,"Telepresence Advanced Media Gateway,Telepresence Mcu Software,Telepresence Server Software,Telepresence Ip Gateway,Telepresence Supervisor Mse 8050 Software,Telepresence Isdn Gw 3241,Telepresence Serial Gateway,Telepresence Ip Vcr 2.4,Telepresence Ip Vcr 3.0,Telepresence Ip Vcr 1.0 Converter",,,0.001560000004246831,false,,false,false,false,,,false,false,,2015-05-25T00:00:00.000Z,0 CVE-2015-0621,https://securityvulnerability.io/vulnerability/CVE-2015-0621,,"Cisco TelePresence MCU devices with software 4.5(1.45) allow remote attackers to cause a denial of service (device reload) via an unspecified series of TCP packets, aka Bug ID CSCur50347.",Cisco,Telepresence Mcu 4500 Series Software,,,0.01355000026524067,false,,false,false,false,,,false,false,,2015-02-18T02:00:00.000Z,0 CVE-2014-3397,https://securityvulnerability.io/vulnerability/CVE-2014-3397,,"The network stack in Cisco TelePresence MCU Software before 4.3(2.30) allows remote attackers to cause a denial of service (memory consumption) via crafted TCP packets, aka Bug ID CSCtz35468.",Cisco,Telepresence Mcu Software,,,0.00675999978557229,false,,false,false,false,,,false,false,,2014-10-19T01:00:00.000Z,0 CVE-2013-1176,https://securityvulnerability.io/vulnerability/CVE-2013-1176,,"The DSP card on Cisco TelePresence MCU 4500 and 4501 devices before 4.3(2.30), TelePresence MCU MSE 8510 devices before 4.3(2.30), and TelePresence Server before 2.3(1.55) does not properly validate H.264 data, which allows remote attackers to cause a denial of service (device reload) via crafted RTP packets in a (1) SIP session or (2) H.323 session, aka Bug IDs CSCuc11328 and CSCub05448.",Cisco,"Telepresence Mcu 4500 Series Software,Telepresence Mcu 4505,Telepresence Mcu 4510,Telepresence Mcu 4515,Telepresence Mcu 4520",,,0.0018100000452250242,false,,false,false,false,,,false,false,,2013-04-18T18:55:00.000Z,0