7.8
CVSSv2

CVE-2011-0388

Published: 25/02/2011 Updated: 09/04/2011
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Cisco TelePresence Recording Server devices with software 1.6.x and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x do not properly restrict remote access to the Java servlet RMI interface, which allows remote malicious users to cause a denial of service (memory consumption and web outage) via multiple crafted requests, aka Bug IDs CSCtg35830 and CSCtg35825.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco telepresence recording server software 1.6.1

cisco telepresence recording server software 1.6.2

cisco telepresence recording server software 1.6.3

cisco telepresence recording server

cisco telepresence multipoint switch software 1.0.4.0

cisco telepresence multipoint switch software 1.1.0

cisco telepresence multipoint switch software 1.1.1

cisco telepresence multipoint switch software 1.1.2

cisco telepresence multipoint switch software 1.5.0

cisco telepresence multipoint switch software 1.5.1

cisco telepresence multipoint switch software 1.5.2

cisco telepresence multipoint switch software 1.5.3

cisco telepresence multipoint switch software 1.5.4

cisco telepresence multipoint switch software 1.5.5

cisco telepresence multipoint switch software 1.5.6

cisco telepresence multipoint switch software 1.6.0

cisco telepresence multipoint switch software 1.6.1

cisco telepresence multipoint switch software 1.6.2

cisco telepresence multipoint switch software 1.6.3

cisco telepresence multipoint switch software 1.6.4

cisco telepresence multipoint switch

Vendor Advisories

Multiple vulnerabilities exist within the Cisco TelePresence Recording Server This security advisory outlines details of the following vulnerabilities: Unauthenticated Java Servlet Access Common Gateway Interface (CGI) Command Injection Unauthenticated Arbitrary File Upload XML-Remote Procedure Call ...
Multiple vulnerabilities exist within the Cisco TelePresence Multipoint Switch This security advisory outlines details of the following vulnerabilities: Unauthenticated Java Servlet Access Unauthenticated Arbitrary File Upload Cisco Discovery Protocol Remote Code Execution Unauthorized Servlet Access Jav ...