Lucene search

K
cve[email protected]CVE-2013-3454
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2013-3454

2022-10-0316:14:45
CWE-255
web.nvd.nist.gov
17
cisco
telepresence
software
default password
pwrecovery account
remote attackers
https requests
bug id cscui43128
nvd

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.2 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

69.0%

Cisco TelePresence System Software 1.10.1 and earlier on 500, 13X0, 1X00, 30X0, and 3X00 devices, and 6.0.3 and earlier on TX 9X00 devices, has a default password for the pwrecovery account, which makes it easier for remote attackers to modify the configuration or perform arbitrary actions via HTTPS requests, aka Bug ID CSCui43128.

Affected configurations

NVD
Node
ciscotelepresence_system_tx9000
OR
ciscotelepresence_system_tx9200
AND
ciscotelepresence_system_softwareRange6.0.3\(33\)
OR
ciscotelepresence_system_softwareMatch1.9.0\(46\)
OR
ciscotelepresence_system_softwareMatch1.9.0.1\(3\)
OR
ciscotelepresence_system_softwareMatch1.9.1\(68\)
OR
ciscotelepresence_system_softwareMatch1.9.2
OR
ciscotelepresence_system_softwareMatch1.9.2\(19\)
OR
ciscotelepresence_system_softwareMatch1.9.3
OR
ciscotelepresence_system_softwareMatch1.9.3\(44\)
OR
ciscotelepresence_system_softwareMatch1.9.4
OR
ciscotelepresence_system_softwareMatch1.9.4\(19\)
OR
ciscotelepresence_system_softwareMatch1.9.5
OR
ciscotelepresence_system_softwareMatch1.9.5\(7\)
OR
ciscotelepresence_system_softwareMatch1.9.6
OR
ciscotelepresence_system_softwareMatch1.9.6\(2\)
OR
ciscotelepresence_system_softwareMatch6.0.0.1\(4\)
OR
ciscotelepresence_system_softwareMatch6.0.1\(50\)
OR
ciscotelepresence_system_softwareMatch6.0.2\(28\)
Node
ciscotelepresence_system_softwareRange1.10.1
OR
ciscotelepresence_system_softwareMatch1.2.3
OR
ciscotelepresence_system_softwareMatch1.2.3\(1101\)
OR
ciscotelepresence_system_softwareMatch1.3.2
OR
ciscotelepresence_system_softwareMatch1.3.2\(1393\)
OR
ciscotelepresence_system_softwareMatch1.4.7
OR
ciscotelepresence_system_softwareMatch1.4.7\(2229\)
OR
ciscotelepresence_system_softwareMatch1.5.1
OR
ciscotelepresence_system_softwareMatch1.5.1\(2082\)
OR
ciscotelepresence_system_softwareMatch1.5.3
OR
ciscotelepresence_system_softwareMatch1.5.3\(2115\)
OR
ciscotelepresence_system_softwareMatch1.5.10
OR
ciscotelepresence_system_softwareMatch1.5.10\(3648\)
OR
ciscotelepresence_system_softwareMatch1.5.11
OR
ciscotelepresence_system_softwareMatch1.5.11\(3659\)
OR
ciscotelepresence_system_softwareMatch1.5.12
OR
ciscotelepresence_system_softwareMatch1.5.12\(3701\)
OR
ciscotelepresence_system_softwareMatch1.5.13
OR
ciscotelepresence_system_softwareMatch1.5.13\(3717\)
OR
ciscotelepresence_system_softwareMatch1.6.0
OR
ciscotelepresence_system_softwareMatch1.6.0\(3954\)
OR
ciscotelepresence_system_softwareMatch1.6.1
OR
ciscotelepresence_system_softwareMatch1.6.2
OR
ciscotelepresence_system_softwareMatch1.6.2\(4023\)
OR
ciscotelepresence_system_softwareMatch1.6.3
OR
ciscotelepresence_system_softwareMatch1.6.3\(4042\)
OR
ciscotelepresence_system_softwareMatch1.6.4
OR
ciscotelepresence_system_softwareMatch1.6.4\(4072\)
OR
ciscotelepresence_system_softwareMatch1.6.5
OR
ciscotelepresence_system_softwareMatch1.6.5\(4097\)
OR
ciscotelepresence_system_softwareMatch1.6.6
OR
ciscotelepresence_system_softwareMatch1.6.6\(4109\)
OR
ciscotelepresence_system_softwareMatch1.6.7
OR
ciscotelepresence_system_softwareMatch1.6.7\(4212\)
OR
ciscotelepresence_system_softwareMatch1.6.8
OR
ciscotelepresence_system_softwareMatch1.6.8\(4222\)
OR
ciscotelepresence_system_softwareMatch1.7.0.1\(4764\)
OR
ciscotelepresence_system_softwareMatch1.7.0.2\(4719\)
OR
ciscotelepresence_system_softwareMatch1.7.1\(4864\)
OR
ciscotelepresence_system_softwareMatch1.7.2\(4937\)
OR
ciscotelepresence_system_softwareMatch1.7.2.1\(2\)
OR
ciscotelepresence_system_softwareMatch1.7.4\(270\)
OR
ciscotelepresence_system_softwareMatch1.7.5\(42\)
OR
ciscotelepresence_system_softwareMatch1.7.6\(4\)
OR
ciscotelepresence_system_softwareMatch1.8.0\(55\)
OR
ciscotelepresence_system_softwareMatch1.8.1\(34\)
OR
ciscotelepresence_system_softwareMatch1.8.2\(11\)
OR
ciscotelepresence_system_softwareMatch1.8.3\(4\)
OR
ciscotelepresence_system_softwareMatch1.9.0\(46\)
OR
ciscotelepresence_system_softwareMatch1.9.0.1\(3\)
OR
ciscotelepresence_system_softwareMatch1.9.1\(68\)
OR
ciscotelepresence_system_softwareMatch1.9.2
OR
ciscotelepresence_system_softwareMatch1.9.3
OR
ciscotelepresence_system_softwareMatch1.9.4
OR
ciscotelepresence_system_softwareMatch1.9.5
OR
ciscotelepresence_system_softwareMatch1.9.6
OR
ciscotelepresence_system_softwareMatch1.10.0
AND
ciscotelepresence_system_1300Match-
OR
ciscotelepresence_system_1300-65Match-
OR
ciscotelepresence_system_3000
OR
ciscotelepresence_system_3010
OR
ciscotelepresence_system_3200
OR
ciscotelepresence_system_3210
OR
ciscotelepresence_system_500-32Match-
OR
ciscotelepresence_system_500-37Match-

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.2 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

69.0%