9
CVSSv2

CVE-2011-0374

Published: 25/02/2011 Updated: 31/03/2011
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x up to and including 1.5.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCtb31659.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco telepresence system software 1.2.3

cisco telepresence system software 1.3.2

cisco telepresence system software 1.4.7

cisco telepresence system software 1.5.1

cisco telepresence system software 1.5.3

cisco telepresence system software 1.5.10

cisco telepresence system software 1.5.11

cisco telepresence system software 1.5.12

cisco telepresence system software 1.5.13

cisco telepresence system 1000

cisco telepresence system 1100

cisco telepresence system 3000

cisco telepresence system 1300 series

cisco telepresence system 3200 series

cisco telepresence system 500 series

Vendor Advisories

Multiple vulnerabilities exist in the Cisco TelePresence solution; each component of the solution is addressed independently in its own advisory This advisory addresses Cisco TelePresence endpoint devices and details the following vulnerabilities: Unauthenticated Common Gateway Interface (CGI) Access CGI Command Injection ...