CVE-2015-0747: Cisco Headend Digital Broadband Delivery System

Medium severity, CVSS 4.3. EPSS: 1.8% chance of exploitation in the next 30 days.

Cisco Conductor for Videoscape 3.0 and Cisco Headend System Release allow remote attackers to inject arbitrary cookies via a crafted HTTP request, aka Bug ID CSCuh25408.

Affected products

  • Cisco Headend Digital Broadband Delivery System: affected versions not specified
  • Cisco Headend System Release: version 2.5 only; version 2.7 only; version 3.2 only; version 3.5 only; version 3.7 only; version i4.3 only
  • Cisco Videoscape Conductor: version 3.0 only

Published 2015-05-30. Last modified 2026-06-17.