Multiple Vulnerabilities in Cisco TelePresence Recording Server

Related Vulnerabilities: CVE-2011-0382   CVE-2011-0383   CVE-2011-0384   CVE-2011-0385   CVE-2011-0386   CVE-2011-0391   CVE-2011-0392   CVE-2011-0379   CVE-2011-0388  

Multiple vulnerabilities exist within the Cisco TelePresence Recording Server. This security advisory outlines details of the following vulnerabilities: Unauthenticated Java Servlet Access Common Gateway Interface (CGI) Command Injection Unauthenticated Arbitrary File Upload XML-Remote Procedure Call (RPC) Arbitrary File Overwrite Cisco Discovery Protocol Remote Code Execution Ad Hoc Recording Denial of Service Java Remote method Invocation (RMI) Denial of Service Unauthenticated XML-RPC Interface Duplicate Issue Identification in Other Cisco TelePresence Advisories The Unauthenticated Java Servlet Access vulnerability affects the Cisco TelePresence Multipoint Switch and Recording Server. The defect that is related to each component is covered in each associated advisory. The Cisco Bug IDs for these defects are as follows: Cisco TelePresence Multipoint Switch - CSCtf42008 Cisco TelePresence Recording Server - CSCtf42005 The Unauthenticated Arbitrary File Upload vulnerability affects the Cisco TelePresence Multipoint Switch and Recording server. The defect that is related to each component is covered in each associated advisory. The Cisco Bug IDs for these defects are as follows: Cisco TelePresence Multipoint Switch - CSCth61065 Cisco TelePresence Recording Server - CSCth85786 The Cisco Discovery Protocol Remote Code Execution vulnerability affects Cisco TelePresence endpoints, Manager, Multipoint Switch, and Recording Server. The defect that is related to each component is covered in each associated advisory. The Cisco Bug IDs for these defects are as follows: Cisco TelePresence endpoint devices - CSCtd75754 Cisco TelePresence Manager - CSCtd75761 Cisco TelePresence Multipoint Switch - CSCtd75766 Cisco TelePresence Recording Server - CSCtd75769 The Java RMI Denial of Service vulnerability affects the Cisco TelePresence Multipoint Switch and Recording Server. The defect that is related to each component is covered in each associated advisory. The Cisco Bug IDs for these defects are as follows: Cisco TelePresence Multipoint Switch - CSCtg35825 Cisco TelePresence Recording Server - CSCtg35830 This advisory is posted at http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20110223-telepresence-ctrs.