Vulnslist

find the latest Cisco vulnerabilities

Multiple Vulnerabilities in Cisco TelePresence Recording Server

cisco-sa-20120711-ctrs · Critical · Published · Updated

Cisco TelePresence Recording Server contains the following vulnerabilities: Cisco TelePresence Malformed IP Packets Denial of Service Vulnerability Cisco TelePresence Web Interface Command Injection Cisco TelePresence Cisco Discovery Protocol Remote Code Execution Vulnerability Exploitation of the Cisco TelePresence Malformed IP Packets Denial of Service Vulnerability may allow a remote, unauthenticated attacker to create a denial of service condition, preventing the product from responding to new connection requests and potentially causing some services and processes to crash. Exploitation of the Cisco TelePresence Web Interface Command Injection may allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system with elevated privileges. Exploitation of the Cisco TelePresence Cisco Discovery Protocol Remote Code Execution Vulnerability may allow allow an unauthenticated, adjacent attacker to execute arbitrary code with elevated privileges. Cisco has released updated software that resolves the command and code execution vulnerabilities.  There are currently no plans to resolve the malformed IP packets denial of service vulnerability, as this product is no longer being actively supported. There are no workarounds that mitigate these vulnerabilities. Customers should contact their Cisco Sales Representative to determine the Business Unit responsible for their Cisco TelePresence Recording Server. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-ctrs

Workarounds

There are no workarounds that mitigate these vulnerabilities.

CVEsCVE-2012-2486, CVE-2012-3073, CVE-2012-3076
Cisco Bug IDsCSCth85804, CSCti21830, CSCti21851, CSCtj19078, CSCtj19086, CSCtj19100, CSCty11219, CSCty11299, CSCty11323, CSCty11338, CSCtz40941, CSCtz40947, CSCtz40953, CSCtz40965
CVSS ScoreBase 7.8
Base 7.8 AV:N/AC:L/Au:N/C:N/I:N/A:C/E:F/RL:OF/RC:C
Base 7.8 AV:N/AC:L/Au:N/C:N/I:N/A:C/E:F/RL:U/RC:C
Base 8.3 AV:A/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C
Base 9.0 AV:N/AC:L/Au:S/C:C/I:C/A:C/E:F/RL:OF/RC:C
Product Names From Source
Cisco TelePresence Recording Server, Cisco TelePresence Manager, Cisco TelePresence Multipoint Switch

Related Products

Product CVE Evidence
Cisco TelePresence Recording Server CVE-2012-3076 Cisco OpenVuln
Cisco TelePresence Recording Server CVE-2012-3073 Cisco OpenVuln
Cisco TelePresence Recording Server CVE-2012-2486 Cisco OpenVuln
Cisco TelePresence Multipoint Switch CVE-2012-3076 Cisco OpenVuln
Cisco TelePresence Multipoint Switch CVE-2012-3073 Cisco OpenVuln
Cisco TelePresence Multipoint Switch CVE-2012-2486 Cisco OpenVuln
Cisco TelePresence Manager CVE-2012-3076 Cisco OpenVuln
Cisco TelePresence Manager CVE-2012-3073 Cisco OpenVuln
Cisco TelePresence Manager CVE-2012-2486 Cisco OpenVuln
Cisco TelePresence CVE-2012-3076 Cisco OpenVuln
Cisco TelePresence CVE-2012-3073 Cisco OpenVuln
Cisco TelePresence CVE-2012-2486 Cisco OpenVuln