7.9
CVSSv2

CVE-2011-0379

Published: 25/02/2011 Updated: 09/04/2011
CVSS v2 Base Score: 7.9 | Impact Score: 10 | Exploitability Score: 5.5
VMScore: 703
Vector: AV:A/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 1.6.x; Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x; Cisco TelePresence endpoint devices with software 1.2.x up to and including 1.6.x; and Cisco TelePresence Manager 1.2.x, 1.3.x, 1.4.x, 1.5.x, and 1.6.2 allows remote malicious users to execute arbitrary code via a crafted Cisco Discovery Protocol packet, aka Bug IDs CSCtd75769, CSCtd75766, CSCtd75754, and CSCtd75761.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco adaptive security appliance software 1.6.0

cisco 5500 series adaptive security appliance

cisco asa 5500

cisco telepresence multipoint switch software 1.0.4.0

cisco telepresence multipoint switch software 1.1.0

cisco telepresence multipoint switch software 1.1.1

cisco telepresence multipoint switch software 1.1.2

cisco telepresence multipoint switch software 1.5.0

cisco telepresence multipoint switch software 1.5.1

cisco telepresence multipoint switch software 1.5.2

cisco telepresence multipoint switch software 1.5.3

cisco telepresence multipoint switch software 1.5.4

cisco telepresence multipoint switch software 1.5.5

cisco telepresence multipoint switch software 1.5.6

cisco telepresence multipoint switch software 1.6.0

cisco telepresence multipoint switch software 1.6.1

cisco telepresence multipoint switch software 1.6.2

cisco telepresence multipoint switch software 1.6.3

cisco telepresence multipoint switch software 1.6.4

cisco telepresence multipoint switch

cisco telepresence system software 1.2.3

cisco telepresence system software 1.3.2

cisco telepresence system software 1.4.7

cisco telepresence system software 1.5.1

cisco telepresence system software 1.5.3

cisco telepresence system software 1.5.10

cisco telepresence system software 1.5.11

cisco telepresence system software 1.5.12

cisco telepresence system software 1.5.13

cisco telepresence system software 1.6.0

cisco telepresence system software 1.6.2

cisco telepresence system software 1.6.3

cisco telepresence system software 1.6.4

cisco telepresence system software 1.6.5

cisco telepresence system software 1.6.6

cisco telepresence system software 1.6.7

cisco telepresence system software 1.6.8

cisco telepresence system 1000

cisco telepresence system 1100

cisco telepresence system 3000

cisco telepresence system 1300 series

cisco telepresence system 3200 series

cisco telepresence system 500 series

cisco telepresence manager 1.5.1

cisco telepresence manager 1.4.0

cisco telepresence manager 1.6.2

cisco telepresence manager 1.5.2

cisco telepresence manager 1.2.0.0

cisco telepresence manager 1.3.2

Vendor Advisories

Multiple vulnerabilities exist in the Cisco TelePresence Manager This security advisory outlines the details of the following vulnerabilities: Simple Object Access Protocol (SOAP) Authentication Bypass Java Remote Method Invocation (RMI) Command Injection Cisco Discovery Protocol Remote Code Execution Duplicat ...
Multiple vulnerabilities exist in the Cisco TelePresence solution; each component of the solution is addressed independently in its own advisory This advisory addresses Cisco TelePresence endpoint devices and details the following vulnerabilities: Unauthenticated Common Gateway Interface (CGI) Access CGI Command Injection ...
Multiple vulnerabilities exist within the Cisco TelePresence Recording Server This security advisory outlines details of the following vulnerabilities: Unauthenticated Java Servlet Access Common Gateway Interface (CGI) Command Injection Unauthenticated Arbitrary File Upload XML-Remote Procedure Call ...
Multiple vulnerabilities exist within the Cisco TelePresence Multipoint Switch This security advisory outlines details of the following vulnerabilities: Unauthenticated Java Servlet Access Unauthenticated Arbitrary File Upload Cisco Discovery Protocol Remote Code Execution Unauthorized Servlet Access Jav ...