Vulnslist

find the latest Cisco vulnerabilities

Multiple Vulnerabilities in Cisco TelePresence Immersive Endpoint Devices

cisco-sa-20120711-cts · Critical · Published · Updated

Cisco TelePresence Endpoint devices contain the following vulnerabilities: Cisco TelePresence API Remote Command Execution Vulnerability Cisco TelePresence Remote Command Execution Vulnerability Cisco TelePresence Cisco Discovery Protocol Remote Code Execution Vulnerability Exploitation of the API Remote Command Execution vulnerability could allow an unauthenticated, adjacent attacker to inject commands into API requests.  The injected commands will be executed by the underlying operating system in an elevated context. Exploitation of the Remote Command Execution vulnerability could allow an authenticated, remote attacker to inject commands into requests made to the Administrative Web interface.  The injected commands will be executed by the underlying operating system in an elevated context. Exploitation of the Cisco TelePresence Cisco Discovery Protocol Remote Code Execution Vulnerability may allow an unauthenticated, adjacent attacker to execute arbitrary code with elevated privileges. Cisco has released software updates that address these vulnerabilities. There are no workarounds that mitigate these vulnerabilities. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-cts

Workarounds

There are no workarounds that mitigate these vulnerabilities.

CVEsCVE-2012-2486, CVE-2012-3074, CVE-2012-3075
Cisco Bug IDsCSCtn99724, CSCtz38382, CSCtz40941, CSCtz40947, CSCtz40953, CSCtz40965
CVSS ScoreBase 8.3
Base 8.3 AV:A/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C
Product Names From Source
Cisco TelePresence Recording Server, Cisco TelePresence Manager, Cisco TelePresence Multipoint Switch

Related Products

Product CVE Evidence
Cisco TelePresence Recording Server CVE-2012-3075 Cisco OpenVuln
Cisco TelePresence Recording Server CVE-2012-3074 Cisco OpenVuln
Cisco TelePresence Recording Server CVE-2012-2486 Cisco OpenVuln
Cisco TelePresence Multipoint Switch CVE-2012-3075 Cisco OpenVuln
Cisco TelePresence Multipoint Switch CVE-2012-3074 Cisco OpenVuln
Cisco TelePresence Multipoint Switch CVE-2012-2486 Cisco OpenVuln
Cisco TelePresence Manager CVE-2012-3075 Cisco OpenVuln
Cisco TelePresence Manager CVE-2012-3074 Cisco OpenVuln
Cisco TelePresence Manager CVE-2012-2486 Cisco OpenVuln
Cisco TelePresence CVE-2012-3075 Cisco OpenVuln
Cisco TelePresence CVE-2012-3074 Cisco OpenVuln
Cisco TelePresence CVE-2012-2486 Cisco OpenVuln