CVE-2014-3324: Cisco Telepresence Server Software
Medium severity, CVSS 4.3. EPSS: 1.5% chance of exploitation in the next 30 days.
Multiple cross-site scripting (XSS) vulnerabilities in the login page in the administrative web interface in Cisco TelePresence Server Software 4.0(2.8) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCup90060.
Affected products
- Cisco Telepresence Server Software: version 3.0(2.24) only; version 3.1(1.98) only; version 4.0(1.57) only; version 4.0(2.8) only
Published 2014-07-26. Last modified 2026-06-17.