Multiple Vulnerabilities in Cisco TelePresence Manager

Related Vulnerabilities: CVE-2011-0380   CVE-2011-0381   CVE-2011-0390   CVE-2011-0379  

Multiple vulnerabilities exist in the Cisco TelePresence Manager. This security advisory outlines the details of the following vulnerabilities: Simple Object Access Protocol (SOAP) Authentication Bypass Java Remote Method Invocation (RMI) Command Injection Cisco Discovery Protocol Remote Code Execution Duplicate Issue Identification in Other Cisco TelePresence Advisories The Cisco Discovery Protocol remote code execution vulnerability affects Cisco TelePresence endpoints, Manager, Multipoint Switch, and Recording Server. The details about how the defect relates to each component are covered in each associated advisory. The Cisco bug IDs for these defects are as follows: Cisco TelePresence endpoint devices - CSCtd75754 Cisco TelePresence Manager - CSCtd75761 Cisco TelePresence Multipoint Switch - CSCtd75766 Cisco TelePresence Recording Server - CSCtd75769 This advisory is posted at http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20110223-telepresence-ctsman.