Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch

cisco-sa-20120711-ctms · High · Published · Updated

Cisco TelePresence Multipoint Switch contains the following vulnerabilities: Cisco TelePresence Malformed IP Packets Denial of Service Vulnerability Cisco TelePresence Cisco Discovery Protocol Remote Code Execution Vulnerability Exploitation of the Cisco TelePresence Malformed IP Packets Denial of Service Vulnerability may allow an unauthenticated, remote attacker to create a denial of service (DoS) condition, causing the product to become unresponsive to new connection requests and potentially leading to termination services and processes. Exploitation of the Cisco TelePresence Cisco Discovery Protocol Remote Code Execution Vulnerability may allow an unauthenticated, adjacent attacker to execute arbitrary code with elevated privileges. Cisco has released software updates that address these vulnerabilities. There are no workarounds that mitigate these vulnerabilities. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-ctms

Cisco advisory · CSAF JSON

Workarounds

There are no workarounds that mitigate these vulnerabilities.

CVEsCVE-2012-2486, CVE-2012-3073
Cisco Bug IDsCSCti21830, CSCti21851, CSCtj19078, CSCtj19086, CSCtj19100, CSCty11219, CSCty11299, CSCty11323, CSCty11338, CSCtz40941, CSCtz40947, CSCtz40953, CSCtz40965
CVSS ScoreBase 7.8
Base 7.8 AV:N/AC:L/Au:N/C:N/I:N/A:C/E:F/RL:OF/RC:C
Base 7.8 AV:N/AC:L/Au:N/C:N/I:N/A:C/E:F/RL:U/RC:C
Base 8.3 AV:A/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C
Product Names From Source
Cisco TelePresence Recording Server, Cisco TelePresence Manager, Cisco TelePresence Multipoint Switch

Related Products

Product CVE Evidence
Cisco TelePresence Recording Server CVE-2012-3073 Cisco OpenVuln
Cisco TelePresence Recording Server CVE-2012-2486 Cisco OpenVuln
Cisco TelePresence Multipoint Switch CVE-2012-3073 Cisco OpenVuln
Cisco TelePresence Multipoint Switch CVE-2012-2486 Cisco OpenVuln
Cisco TelePresence Manager CVE-2012-3073 Cisco OpenVuln
Cisco TelePresence Manager CVE-2012-2486 Cisco OpenVuln
Cisco TelePresence CVE-2012-3073 Cisco OpenVuln
Cisco TelePresence CVE-2012-2486 Cisco OpenVuln