XML External Entity (XXE) Vulnerability in Cisco TelePresence Management Suite (TMS) 14.3(.2) and earlier

XML External Entity (XXE) Vulnerability in Cisco TelePresence Management Suite (TMS) 14.3(.2) and earlier

CVE-2015-0620 · MEDIUM Severity

AV:N/AC:L/AU:S/C:N/I:N/A:P

The XML parser in Cisco TelePresence Management Suite (TMS) 14.3(.2) and earlier does not properly handle external entities, which allows remote authenticated users to cause a denial of service via POST requests, aka Bug ID CSCus51494.

Learn more about our Cis Benchmark Audit For Cisco.