{"schema_version":"public-product-v1.1","generated_at":"2026-07-21T10:39:16Z","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","advisory":{"id":"cisco-sa-20160504-tpxml","slug":"cisco-sa-20160504-tpxml","vendor":"Cisco","title":"Cisco TelePresence XML Application Programming Interface Authentication Bypass Vulnerability","summary":"A vulnerability in the XML application programming interface&nbsp;(API) of Cisco&nbsp;TelePresence Codec&nbsp;(TC) and Collaboration Endpoint&nbsp;(CE) Software could allow an unauthenticated, remote attacker to bypass authentication and access a targeted system through the API. The vulnerability is due to improper implementation of authentication mechanisms for the XML API of the affected software. An attacker could exploit this vulnerability by sending a crafted HTTP request to the XML API. A successful exploit could allow the attacker to perform unauthorized configuration changes or issue control commands to the affected system by using the API. Cisco has released software updates that address this vulnerability. There is a workaround that addresses this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160504-tpxml","severity":"Critical","published_at":"2016-05-04T16:00:00Z","updated_at":"2016-05-04T16:00:00Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160504-tpxml","csaf_url":"https://sec.cloudapps.cisco.com/security/center/contentjson/CiscoSecurityAdvisory/cisco-sa-20160504-tpxml/csaf/cisco-sa-20160504-tpxml.json","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure."},"freshness":{"last_source_refreshed_at":"2026-07-21T05:16:34Z","latest_source_refresh_at":"2026-07-21T05:16:34Z","oldest_source_refresh_at":"2026-07-21T03:00:03Z","all_sources_fresh":true,"sources":[{"source":"cisco_advisories","label":"Cisco advisories","last_success_at":"2026-07-21T03:00:03Z","stale":false},{"source":"cisco_csaf","label":"Cisco CSAF","last_success_at":"2026-07-21T05:14:24Z","stale":false},{"source":"nvd_cves","label":"NVD CVEs","last_success_at":"2026-07-21T05:16:30Z","stale":false},{"source":"cisa_kev","label":"CISA KEV","last_success_at":"2026-07-21T05:16:31Z","stale":false},{"source":"first_epss","label":"EPSS","last_success_at":"2026-07-21T05:16:34Z","stale":false}]},"summary":{"cve_count":1,"visible_product_count":1,"public_evidence_count":1,"kev_count":0,"highest_epss":0.01778},"cves":[{"id":"CVE-2016-1387","kev":false,"epss":{"score":0.01778,"percentile":0.75801,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:33Z"}}],"public_evidence":[{"product":{"name":"Cisco TelePresence TC Software","slug":"cisco-telepresence-tc-software","vendor":"Cisco"},"cve":{"id":"CVE-2016-1387"},"evidence_type":"structured_affected","evidence_label":{"scope":"CSAF product evidence","label":"product_status known affected"},"evidence_source":"Cisco CSAF","source":"Cisco CSAF","source_document_fetched_at":"2026-07-20T04:58:10Z","csaf_status":"known_affected","csaf_product_status":"known_affected","csaf_product_status_path":"vulnerabilities[].product_status.known_affected","raw_product_name":"Cisco TelePresence TC Software","exposure_verdict":"not_assessed","verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","exposure_verdict_reason":"Public evidence does not evaluate exact release, platform, enabled features, configuration, compensating controls, or live exposure.","kev":false,"epss":{"score":0.01778,"score_date":"2026-07-20","updated_at":"2026-07-21T05:16:33Z"},"published_at":"2016-05-04T16:00:00Z","updated_at":"2016-05-04T16:00:00Z","advisory_updated_at":"2016-05-04T16:00:00Z","source_url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160504-tpxml","row_display_order":1}]}