Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

Cisco TelePresence VX Clinical Assistant Administrative Password Reset Vulnerability

cisco-sa-20131106-tvxca · Critical · Published · Updated

A vulnerability in the WIL-A module of Cisco TelePresence VX Clinical Assistant could allow an unauthenticated, remote attacker to log in as the admin user of the device using a blank password. The vulnerability is due to a coding error that resets the password for the admin user to a blank password on every reboot. An attacker could exploit this vulnerability by logging in to the administrative interface as the admin user with a blank password. Cisco has released software updates that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20131106-tvxca

Cisco advisory · CSAF JSON

Workarounds

There are no workarounds for this vulnerability.

CVEsCVE-2013-5558
Cisco Bug IDsCSCuj17238
CVSS ScoreBase 10.0
Base 10.0 AV:N/AC:L/Au:N/C:C/I:C/A:C/E:H/RL:OF/RC:C
Product Names From Source
Cisco TelePresence VX Clinical Assistant

Related Products

Product CVE Evidence
Cisco TelePresence VX Clinical Assistant CVE-2013-5558 Cisco OpenVuln
Cisco TelePresence CVE-2013-5558 Cisco OpenVuln