5
CVSSv2

CVE-2015-0770

Published: 07/06/2015 Updated: 04/01/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

CRLF injection vulnerability in Cisco TelePresence TC 6.x prior to 6.3.4 and 7.x prior to 7.3.3 on Integrator C SX20 devices allows remote malicious users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL, aka Bug ID CSCut79341.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco telepresence tc software 6.3.1

cisco telepresence tc software 6.3.2

cisco telepresence tc software 6.3.3

cisco telepresence tc software 7.3.2

cisco telepresence tc software 7.2.0

cisco telepresence tc software 7.2.1

cisco telepresence tc software 7.1.4

cisco telepresence tc software 7.3.0

cisco telepresence tc software 7.1.2

cisco telepresence tc software 7.1.0

cisco telepresence tc software 7.3.1

cisco telepresence tc software 7.1.3

cisco telepresence tc software 7.1.1

cisco telepresence tc software 6.3.0

Vendor Advisories

A vulnerability in Cisco TelePresence Collaboration Desk and Room Endpoints running TC Software could allow an unauthenticated, remote attacker to conduct HTTP response splitting attacks The vulnerability is due to insufficient user input sanitization performed by the affected software while processing HTTP requests An unauthenticated, remote at ...