Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

Cisco TelePresence IX5000 Series Web Management Vulnerability

Cisco-SA-20150211-CVE-2015-0611 · Medium · Published · Updated

A vulnerability in the administrative web management portal of Cisco TelePresence IX5000 Series devices could allow an authenticated, remote attacker to gain unauthorized access to certain pages in the web interface. The vulnerability is due to a failure to properly restrict access given to the device recovery account. An attacker could exploit this vulnerability by authenticating with the affected account. Successful exploitation could allow the attacker to gain privileges equal to the HelpDesk account on the administrative web interface. Cisco has confirmed the vulnerability in a security notice and released software updates. To exploit this vulnerability, an attacker must authenticate with the recovery account on the targeted device. This requirement may reduce the likelihood of a successful exploit.

Cisco advisory · CSAF JSON

Workarounds

Administrators are advised to apply the appropriate updates.

Administrators are advised to allow only trusted users to have network access.

Administrators are advised to allow only privileged users to access administration or management systems.

Administrators are advised to monitor affected systems.

CVEsCVE-2015-0611
Cisco Bug IDsCSCus74174
CVSS ScoreBase 6.5
Base 6.5 AV:N/AC:L/Au:S/C:P/I:P/A:P/E:H/RL:OF/RC:C
Product Names From Source
Cisco TelePresence System Software

Related Products

Product CVE Evidence
Cisco TelePresence System Software CVE-2015-0611 Cisco OpenVuln
Cisco TelePresence IX5000 CVE-2015-0611 Cisco OpenVuln
Cisco TelePresence CVE-2015-0611 Cisco OpenVuln