Release Notes
Resolved issues
Cisco TelePresence Conductor Release Notes (XC2.3.1) Page 11 of 21
Identifier Description
CSCuo20306 Symptom: Cisco Telepresence Conductor includes a version of openssl that is affected by the
vulnerability identified by the Common Vulnerability and Exposures (CVE) ID CVE-2014-0160.
This bug has been opened to address the potential impact on this product.
Conditions: Device with default configuration. The following Cisco Telepresence Conductor
versions are affected by this vulnerability: XC2.0 XC2.1 XC2.2 XC2.2.1
Workaround: Not currently available.
Further Problem Description: Additional details about this vulnerability can be found at
http://cve.mitre.org/cve/cve.html
PSIRT Evaluation: The Cisco PSIRT has assigned this bug the following CVSS version 2 score.
The Base and Temporal CVSS scores as of the time of evaluation are 5/5:
https://intellishield.cisco.com/security/alertmanager/cvss?target=new&version=2.0&vector=
AV:N/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:U/RC:C The Cisco PSIRT has assigned this score based on
information obtained from multiple sources. This includes the CVSS score assigned by the third-
party vendor when available. The CVSS score assigned may not reflect the actual impact on the
Cisco Product. CVE-2014-0160 has been assigned to document this issue. Additional
information on Cisco's security vulnerability policy can be found at the following URL:
http://www.cisco.com/web/about/security/psirt/security_vulnerability_policy.html
Resolved in XC2.2.1
There are no issues that were resolved in XC2.2.1.
Resolved in XC2.2
The following issues were found in previous releases and were resolved in XC2.2:
Identifier Description
CSCuh98153 There was an inconsistency in the CiscoTelePresence Conductor with Cisco Unified
Communications Manager Deployment Guide (XC2.1) in regards to the recommended
SIPsetting on the TelePresence Server.This has been corrected in the XC2.2 version of the
deployment guide.
CSCuh95327 The TelePresence Conductor deployment guides did not mention specifically that multiscreen
auto-dialed participants are not supported.This has been corrected in the XC2.2 version of the
deployment guide.
CSCuh30073 The TelePresence Conductor online help pages contained some incorrect regular expression
examples. These have been corrected in the XC2.2 version of the online help.
CSCug78943 When configuring two TelePresence Server conference pools in a prioritized list using Service
Preferences on TelePresence Conductor, conferences were only ever placed in the first pool.
Lower priority pools were not used. This has been fixed inXC2.2.
CSCui42333 Failure to make a call via TelePresence Conductor (i.e. scheduled call from TMS) when the dial-
out URL contained unicode strings. This has been fixed in XC2.2.
CSCug62478 The conference bridge status page on Telepresence Conductor sometimes reported an incorrect
number of TelePresence Server screen licenses.This has been fixed in XC2.2.
CSCuf38907 Enhancement request for TelePresence Conductor to support auto detection of endpoint
multiscreen capabilities via TIP. This feature was added inXC2.2 (Note that it still requires
"Provision for multiscreen" to be set).