CVE-2017-3815

Severity CVSS v4.0:
Pending analysis
Type:
CWE-319 Cleartext Transmission of Sensitive Information
Publication date:
17/03/2017
Last modified:
20/04/2025

Description

An API Privilege vulnerability in Cisco TelePresence Server Software could allow an unauthenticated, remote attacker to emulate Cisco TelePresence Server endpoints. Affected Products: This vulnerability affects Cisco TelePresence Server MSE 8710 Processors that are running a software release prior to Cisco TelePresence Software Release 4.3 and are running in locally managed mode. The vulnerable API was deprecated in Cisco TelePresence Software Release 4.3. More Information: CSCvc37616.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cisco:telepresence_server_software:4.2\(4.17\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:telepresence_server_software:4.2\(4.18\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:telepresence_server_software:4.2\(4.19\):*:*:*:*:*:*:*