Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices

Related Vulnerabilities: CVE-2011-0372   CVE-2011-0373   CVE-2011-0374   CVE-2011-0375   CVE-2011-0376   CVE-2011-0377   CVE-2011-0378   CVE-2011-0379  

Multiple vulnerabilities exist in the Cisco TelePresence solution; each component of the solution is addressed independently in its own advisory. This advisory addresses Cisco TelePresence endpoint devices and details the following vulnerabilities: Unauthenticated Common Gateway Interface (CGI) Access CGI Command Injection TFTP Information Disclosure Malicious IP Address Injection XML-Remote Procedure Call (RPC) Command Injection Cisco Discovery Protocol Remote Code Execution Duplicate Issue Identification in Other Cisco TelePresence Advisories The Cisco Discovery Protocol Remote Code Execution vulnerability affects Cisco TelePresence endpoint devices, Manager, Multipoint Switch, and Recording Server. The defect that is related to each component is covered in each associated advisory. The Cisco bug IDs for these defects are as follows: Cisco TelePresence endpoint devices (CSCtd75754) Cisco TelePresence Manager (CSCtd75761) Cisco TelePresence Multipoint Switch (CSCtd75766) Cisco TelePresence Recording Server (CSCtd75769) This advisory is posted at http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20110223-telepresence-cts.