Lucene search

K
ciscoCiscoCISCO-SA-20120711-CTS
HistoryJul 11, 2012 - 4:00 p.m.

Multiple Vulnerabilities in Cisco TelePresence Immersive Endpoint Devices

2012-07-1116:00:00
tools.cisco.com
17

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

EPSS

0.019

Percentile

88.6%

Cisco TelePresence Endpoint devices contain the following vulnerabilities:

Cisco TelePresence API Remote Command Execution Vulnerability
Cisco TelePresence Remote Command Execution Vulnerability
Cisco TelePresence Cisco Discovery Protocol Remote Code Execution Vulnerability

Exploitation of the API Remote Command Execution vulnerability could allow an unauthenticated, adjacent attacker to inject commands into API requests. The injected commands will be executed by the underlying operating system in an elevated context.

Exploitation of the Remote Command Execution vulnerability could allow an authenticated, remote attacker to inject commands into requests made to the Administrative Web interface. The injected commands will be executed by the underlying operating system in an elevated context.

Exploitation of the Cisco TelePresence Cisco Discovery Protocol Remote Code Execution Vulnerability may allow an unauthenticated, adjacent attacker to execute arbitrary code with elevated privileges.

Cisco has released software updates that address these vulnerabilities.

There are no workarounds that mitigate these vulnerabilities.

This advisory is available at the following link:

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-cts[“https://tvce.cisco.com/security/AIMS/https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-cts”]

Affected configurations

Vulners
Node
ciscotelepresence_recording_serverMatchany
OR
ciscotelepresence_managerMatchany
OR
ciscotelepresence_multipoint_switchMatchany
OR
ciscotelepresence_recording_serverMatchany
OR
ciscotelepresence_managerMatchany
OR
ciscotelepresence_multipoint_switchMatchany
VendorProductVersionCPE
ciscotelepresence_recording_serveranycpe:2.3:h:cisco:telepresence_recording_server:any:*:*:*:*:*:*:*
ciscotelepresence_manageranycpe:2.3:a:cisco:telepresence_manager:any:*:*:*:*:*:*:*
ciscotelepresence_multipoint_switchanycpe:2.3:h:cisco:telepresence_multipoint_switch:any:*:*:*:*:*:*:*

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

EPSS

0.019

Percentile

88.6%

Related for CISCO-SA-20120711-CTS