Vulnslist

find the latest Cisco vulnerabilities

Multiple Vulnerabilities in Cisco TelePresence TC and TE Software

cisco-sa-20140430-tcte · Critical · Published · Updated

Cisco TelePresence TC and TE Software are affected by the following vulnerabilities: Six Session Initiation Protocol (SIP) denial of service vulnerabilities Cisco TelePresence TC and TE Software DNS Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Input Validation Vulnerability Cisco TelePresence TC and TE Software tshell Command Injection Vulnerability Cisco TelePresence TC and TE Software Heap Overflow Vulnerability Cisco TelePresence TC and TE Software U-Boot Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Unauthenticated Serial Port Access Vulnerability Cisco TelePresence TC H.225 Denial of Service Vulnerability Successful exploitation of these vulnerabilities could allow an attacker to cause the affected system to reload, execute arbitrary commands or obtain privileged access to the affected system. Note: This security advisory does not provide information about the OpenSSL TLS Heartbeat Read Overrun Vulnerability identified by CVE-2014-0160 (also known as Heartbleed).  For additional information on Cisco products affected by the Heartbleed vulnerability, refer to the Cisco Security Advisory available at the following link:  https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140409-heartbleed Cisco has released software updates that address these vulnerabilities. There are no workarounds that mitigate these vulnerabilities. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140430-tcte

Cisco advisory · CSAF JSON

Workarounds

There are no workarounds that mitigate these vulnerabilities.

CVEsCVE-2014-0160, CVE-2014-2162, CVE-2014-2163, CVE-2014-2164, CVE-2014-2165, CVE-2014-2166, CVE-2014-2167, CVE-2014-2168, CVE-2014-2169, CVE-2014-2170, CVE-2014-2171, CVE-2014-2172, CVE-2014-2173, CVE-2014-2175
Cisco Bug IDsCSCto70562, CSCtq72699, CSCtq78849, CSCty44804, CSCua64961, CSCua86589, CSCub67692, CSCub67693, CSCud29566, CSCud81796, CSCue60202, CSCue60211, CSCuj94651
CVSS ScoreBase 7.8
Base 7.8 AV:N/AC:L/Au:N/C:N/I:N/A:C/E:F/RL:OF/RC:C
Base 7.6 AV:N/AC:H/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C
Base 9.0 AV:N/AC:L/Au:S/C:C/I:C/A:C/E:F/RL:OF/RC:C
Base 10.0 AV:N/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C
Base 6.6 AV:L/AC:M/Au:S/C:C/I:C/A:C/E:F/RL:OF/RC:C
Base 7.2 AV:L/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C
Product Names From Source
Cisco TelePresence TC Software

Related Products

Product CVE Evidence
Cisco TelePresence TC Software CVE-2014-0160 Cisco OpenVuln
Cisco TelePresence CVE-2014-0160 Cisco OpenVuln
Cisco TelePresence TC Software CVE-2014-2175 Cisco OpenVuln
Cisco TelePresence TC Software CVE-2014-2173 Cisco OpenVuln
Cisco TelePresence TC Software CVE-2014-2172 Cisco OpenVuln
Cisco TelePresence TC Software CVE-2014-2171 Cisco OpenVuln
Cisco TelePresence TC Software CVE-2014-2170 Cisco OpenVuln
Cisco TelePresence TC Software CVE-2014-2169 Cisco OpenVuln
Cisco TelePresence TC Software CVE-2014-2168 Cisco OpenVuln
Cisco TelePresence TC Software CVE-2014-2167 Cisco OpenVuln
Cisco TelePresence TC Software CVE-2014-2166 Cisco OpenVuln
Cisco TelePresence TC Software CVE-2014-2165 Cisco OpenVuln
Cisco TelePresence TC Software CVE-2014-2164 Cisco OpenVuln
Cisco TelePresence TC Software CVE-2014-2163 Cisco OpenVuln
Cisco TelePresence TC Software CVE-2014-2162 Cisco OpenVuln
Cisco TelePresence CVE-2014-2175 Cisco OpenVuln
Cisco TelePresence CVE-2014-2173 Cisco OpenVuln
Cisco TelePresence CVE-2014-2172 Cisco OpenVuln
Cisco TelePresence CVE-2014-2171 Cisco OpenVuln
Cisco TelePresence CVE-2014-2170 Cisco OpenVuln
Cisco TelePresence CVE-2014-2169 Cisco OpenVuln
Cisco TelePresence CVE-2014-2168 Cisco OpenVuln
Cisco TelePresence CVE-2014-2167 Cisco OpenVuln
Cisco TelePresence CVE-2014-2166 Cisco OpenVuln
Cisco TelePresence CVE-2014-2165 Cisco OpenVuln
Cisco TelePresence CVE-2014-2164 Cisco OpenVuln
Cisco TelePresence CVE-2014-2163 Cisco OpenVuln
Cisco TelePresence CVE-2014-2162 Cisco OpenVuln