9.3
CVSSv2

CVE-2011-0386

Published: 25/02/2011 Updated: 17/08/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The XML-RPC implementation on Cisco TelePresence Recording Server devices with software 1.6.x and 1.7.x prior to 1.7.1 allows remote malicious users to overwrite files and consequently execute arbitrary code via a malformed request, aka Bug ID CSCti50739.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco telepresence_recording_server_software 1.6.2

cisco telepresence_recording_server_software 1.7.1

cisco telepresence_recording_server_software 1.7.0

cisco telepresence_recording_server_software 1.6.1

cisco telepresence_recording_server_software 1.6.3

cisco telepresence_recording_server

Vendor Advisories

Multiple vulnerabilities exist within the Cisco TelePresence Recording Server This security advisory outlines details of the following vulnerabilities: Unauthenticated Java Servlet Access Common Gateway Interface (CGI) Command Injection Unauthenticated Arbitrary File Upload XML-Remote Procedure Call ...