First published: Fri Mar 17 2017(Updated: )
An API Privilege vulnerability in Cisco TelePresence Server Software could allow an unauthenticated, remote attacker to emulate Cisco TelePresence Server endpoints. Affected Products: This vulnerability affects Cisco TelePresence Server MSE 8710 Processors that are running a software release prior to Cisco TelePresence Software Release 4.3 and are running in locally managed mode. The vulnerable API was deprecated in Cisco TelePresence Software Release 4.3. More Information: CSCvc37616.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco TelePresence Server | =4.2\(4.17\) | |
Cisco TelePresence Server | =4.2\(4.18\) | |
Cisco TelePresence Server | =4.2\(4.19\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3815 has been rated as a high severity vulnerability due to its potential to allow unauthorized access to Cisco TelePresence Server Software.
To fix CVE-2017-3815, update the Cisco TelePresence Server Software to a patched version beyond 4.2(4.19).
CVE-2017-3815 affects Cisco TelePresence Server Software versions 4.2(4.17), 4.2(4.18), and 4.2(4.19) on MSE 8710 Processors.
Yes, CVE-2017-3815 can be exploited remotely by an unauthenticated attacker through the API.
CVE-2017-3815 is classified as an API Privilege vulnerability.