CVSS2
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:A/AC:L/Au:N/C:C/I:C/A:C
AI Score
Confidence
Low
EPSS
Percentile
48.8%
The XML-RPC implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a TCP request, related to a “command injection vulnerability,” aka Bug ID CSCtb52587.
Vendor | Product | Version | CPE |
---|---|---|---|
cisco | telepresence_system_software | 1.2.3 | cpe:2.3:a:cisco:telepresence_system_software:1.2.3:*:*:*:*:*:*:* |
cisco | telepresence_system_software | 1.3.2 | cpe:2.3:a:cisco:telepresence_system_software:1.3.2:*:*:*:*:*:*:* |
cisco | telepresence_system_software | 1.4.7 | cpe:2.3:a:cisco:telepresence_system_software:1.4.7:*:*:*:*:*:*:* |
cisco | telepresence_system_software | 1.5.1 | cpe:2.3:a:cisco:telepresence_system_software:1.5.1:*:*:*:*:*:*:* |
cisco | telepresence_system_software | 1.5.3 | cpe:2.3:a:cisco:telepresence_system_software:1.5.3:*:*:*:*:*:*:* |
cisco | telepresence_system_software | 1.5.10 | cpe:2.3:a:cisco:telepresence_system_software:1.5.10:*:*:*:*:*:*:* |
cisco | telepresence_system_software | 1.5.11 | cpe:2.3:a:cisco:telepresence_system_software:1.5.11:*:*:*:*:*:*:* |
cisco | telepresence_system_software | 1.5.12 | cpe:2.3:a:cisco:telepresence_system_software:1.5.12:*:*:*:*:*:*:* |
cisco | telepresence_system_software | 1.5.13 | cpe:2.3:a:cisco:telepresence_system_software:1.5.13:*:*:*:*:*:*:* |
cisco | telepresence_system_1000 | * | cpe:2.3:h:cisco:telepresence_system_1000:*:*:*:*:*:*:*:* |