<Past |
Future> |
4.0 (x) |
Approved w/Constraints [2, 3, 4] |
Approved w/Constraints [2, 3, 4] |
Approved w/Constraints [2, 3, 4] |
Approved w/Constraints [2, 3, 4] |
Approved w/Constraints [3, 4] |
Approved w/Constraints [3, 4] |
Divest [3, 4] |
Divest [3, 4] |
Divest [3, 4, 5, 6] |
Divest [3, 4, 5, 6] |
Unapproved |
Unapproved |
4.1 (x) |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Approved w/Constraints [3, 4] |
Approved w/Constraints [3, 4] |
Approved w/Constraints [3, 4] |
Approved w/Constraints [3, 4] |
Divest [3, 4, 5, 6] |
Divest [3, 4, 5, 6] |
Divest [3, 4, 5, 6] |
Divest [4, 5, 7, 8] |
4.2 (x) |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Approved w/Constraints [3, 4] |
Approved w/Constraints [3, 4] |
Approved w/Constraints [3, 4] |
Approved w/Constraints [3, 4] |
Approved w/Constraints [3, 4, 5, 6] |
Approved w/Constraints [3, 4, 5, 6] |
Divest [3, 4, 5, 6] |
Divest [4, 5, 7, 8] |
4.3 (x) |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Approved w/Constraints [3, 4, 5, 6] |
Approved w/Constraints [3, 4, 5, 6] |
Approved w/Constraints [3, 4, 5, 6] |
Approved w/Constraints [4, 5, 7, 8] |
4.4 (x) |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Unapproved |
Approved w/Constraints [3, 4, 5, 6] |
Approved w/Constraints [3, 4, 5, 6] |
Approved w/Constraints [3, 4, 5, 6] |
Approved w/Constraints [4, 5, 7, 8] |
| | [1] | Only instances of this technology that have been deployed may continue to use this technology. No further expansion or use of this technology is permitted without a waiver from the Architecture and Engineering Review Board (AERB) and expressed authorization from the Assistant Secretary/Chief Information Officer or the Principal Deputy Assistant Secretary for the Office of Information and Technology. | | [2] | CVE-2014-3324: Multiple cross-site scripting (XSS) vulnerabilities in the login page in the administrative web interface in Cisco TelePresence Server Software 4.0(2.8) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCup90060
CVE-2013-1176: The DSP card on Cisco TelePresence MCU 4500 and 4501 devices before 4.3(2.30), TelePresence MCU MSE 8510 devices before 4.3(2.30), and TelePresence Server before 2.3(1.55) does not properly validate H.264 data, which allows remote attackers to cause a denial of service (device reload) via crafted RTP packets in a (1) SIP session or (2) H.323 session, aka Bug IDs CSCuc11328 and CSCub05448. | | [3] | Veterans Affairs (VA) users must ensure VA sensitive data is properly protected in compliance with all VA regulations. All instances of deployment using this technology should be reviewed by the local ISO (Information Security Officer) to ensure compliance with VA Handbook 6500. | | [4] | Due to National Institute of Standards and Technology (NIST) identified security vulnerabilities, extra vigilance should be applied to ensure the versions remain properly patched to mitigate known and future vulnerabilities. The local ISO can provide assistance in reviewing the NIST vulnerabilities. | | [5] | New installations or major expansions of this technology that transmit data over the VA Wide Area Network (WAN) must complete a Systems Engineering Design Review (SEDR) (contact VA e-mail: VA IT ESE SEDR SEG) prior to implementation to ensure proper compliance to VA network design and usage requirements. | | [6] | Due to potential information security risks, cloud based technologies may not be used without an Enterprise Security Change Control Board (ESCCB) approval. This body is in part responsible for ensuring organizational information, Personally Identifiable Information (PII), Protected Health Information (PHI), and VA sensitive data are not compromised. (Ref: VA Directive 6004, VA Directive 6517, VA Directive 6513 and VA Directive 6102). | | [7] | Veterans Affairs (VA) users must ensure VA sensitive data is properly protected in compliance with all VA regulations. All instances of deployment using this technology should be reviewed by the local ISO (Information Security Officer) to ensure compliance with VA Handbook 6500. | | [8] | Due to potential information security risks, cloud based technologies may not be used without the approval of the VA Enterprise Cloud Services (ECS) Group. This body is in part responsible for ensuring organizational information, Personally Identifiable Information (PII), Protected Health Information (PHI), and VA sensitive data are not compromised. (Ref: VA Directive 6004, VA Directive 6517, VA Directive 6513 and VA Directive 6102). |
|
Note: |
The end of support date for all TelePresence Server software according to the vendor and the vendor website is 2/28/2021. This technology will be unapproved at that time. |