Lucene search

K
ciscoCiscoCISCO-SA-20130529-CVE-2013-1246
HistoryMay 29, 2013 - 6:39 p.m.

Cisco TelePresence System t-shell Denial of Service Vulnerability

2013-05-2918:39:54
tools.cisco.com
29

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:N/I:N/A:C

EPSS

0.001

Percentile

44.2%

A vulnerability in the
t-shell implementation of Cisco TelePresence System Software could allow
an authenticated, remote attacker to exhaust the available
memory and create a denial of service (DoS) condition.

The vulnerability is due to improper handling of orphaned
t-shell sessions. An attacker could exploit this vulnerability
by opening several Secure Shell (SSH) sessions with the affected
system. An exploit could allow the attacker to consume available
memory; therefore, the affected system may become
unreachable and unable to function properly. A hard reboot is
needed to restore complete functionality.

Cisco has confirmed the vulnerability in a Security Notice and software updates are available.

To exploit this vulnerability, the attacker must authenticate to a targeted system. This access requirement limits the possibility of a successful exploit.

Customers are advised to review the bug report in the “Vendor Announcements” section for a current list of affected versions.

Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Affected configurations

Vulners
Node
ciscotelepresence_system_softwareMatchany
OR
ciscotelepresence_system_softwareMatchany
VendorProductVersionCPE
ciscotelepresence_system_softwareanycpe:2.3:a:cisco:telepresence_system_software:any:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:N/I:N/A:C

EPSS

0.001

Percentile

44.2%

Related for CISCO-SA-20130529-CVE-2013-1246