Vulnslist

find the latest Cisco vulnerabilities

Cisco IP Video Phone E20 Default Root Account

cisco-sa-20120118-te · Critical · Published · Updated

Cisco TelePresence Software version TE 4.1.0 contains a default account vulnerability that could allow an unauthenticated, remote attacker to take complete control of the affected device. The vulnerability is due to an architectural change that was made in the way the system maintains administrative accounts. During the process of upgrading a Cisco IP Video Phone E20 device to TE 4.1.0, an unsecured default account may be introduced. An attacker who is able to take advantage of this vulnerability could log in to the device as the root user and perform arbitrary actions with elevated privileges. Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are available. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120118-te

Cisco advisory · CSAF JSON

Workarounds

No workaround information imported yet.

CVEsCVE-2011-4659
Cisco Bug IDsCSCtw69889
CVSS ScoreBase 10.0
Base 10.0 AV:N/AC:L/Au:N/C:C/I:C/A:C/E:H/RL:OF/RC:C
Product Names From Source
Cisco TelePresence

Related Products

Product CVE Evidence
Cisco TelePresence CVE-2011-4659 Cisco OpenVuln