{"schema_version":"public-product-v1.1","generated_at":"2026-07-21T10:12:46Z","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","advisory":{"id":"Cisco-SA-20140123-CVE-2014-0675","slug":"cisco-sa-20140123-cve-2014-0675","vendor":"Cisco","title":"Cisco TelePresence Video Communication Server Expressway Default SSL Certificate Vulnerability","summary":"A vulnerability in the Cisco TelePresence Video Communication Server (VCS) Expressway could allow an unauthenticated, remote attacker to execute a man-in-the-middle (MITM) attack between one or more affected devices. The vulnerability occurs because the same default SSL certificate is used across all Cisco TelePresence VCS Expressway devices. An attacker could exploit this vulnerability by using the default SSL certificate to intercept, decrypt, read, and write information between one or more of the affected devices. Cisco has confirmed the vulnerability in a security notice and released software updates. It is likely that one or more affected devices that an attacker could attempt to exploit would be placed on trusted, internal networks behind firewall restrictions. An attacker may require access to this network, which may reduce the likelihood of a successful exploit.","severity":"Medium","published_at":"2014-01-23T16:44:48Z","updated_at":"2014-01-23T16:44:48Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20140123-CVE-2014-0675","csaf_url":"https://sec.cloudapps.cisco.com/security/center/contentjson/CiscoSecurityAdvisory/Cisco-SA-20140123-CVE-2014-0675/csaf/Cisco-SA-20140123-CVE-2014-0675.json","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure."},"freshness":{"last_source_refreshed_at":"2026-07-21T05:16:34Z","latest_source_refresh_at":"2026-07-21T05:16:34Z","oldest_source_refresh_at":"2026-07-21T03:00:03Z","all_sources_fresh":true,"sources":[{"source":"cisco_advisories","label":"Cisco advisories","last_success_at":"2026-07-21T03:00:03Z","stale":false},{"source":"cisco_csaf","label":"Cisco CSAF","last_success_at":"2026-07-21T05:14:24Z","stale":false},{"source":"nvd_cves","label":"NVD CVEs","last_success_at":"2026-07-21T05:16:30Z","stale":false},{"source":"cisa_kev","label":"CISA KEV","last_success_at":"2026-07-21T05:16:31Z","stale":false},{"source":"first_epss","label":"EPSS","last_success_at":"2026-07-21T05:16:34Z","stale":false}]},"summary":{"cve_count":1,"visible_product_count":1,"public_evidence_count":1,"kev_count":0,"highest_epss":0.01603},"cves":[{"id":"CVE-2014-0675","kev":false,"epss":{"score":0.01603,"percentile":0.73164,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:32Z"}}],"public_evidence":[{"product":{"name":"Cisco TelePresence Video Communication Server (VCS)","slug":"cisco-telepresence-video-communication-server-vcs","vendor":"Cisco"},"cve":{"id":"CVE-2014-0675"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-20T04:58:42Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"Cisco TelePresence Video Communication Server (VCS)","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"epss":{"score":0.01603,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:32Z"},"published_at":"2014-01-23T16:44:48Z","updated_at":"2014-01-23T16:44:48Z","advisory_updated_at":"2014-01-23T16:44:48Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/Cisco-SA-20140123-CVE-2014-0675","row_display_order":1}]}