8.3
CVSSv2

CVE-2014-0661

Published: 22/01/2014 Updated: 29/08/2017
CVSS v2 Base Score: 8.3 | Impact Score: 10 | Exploitability Score: 6.5
VMScore: 739
Vector: AV:A/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The System Status Collection Daemon (SSCD) in Cisco TelePresence System 500-37, 1000, 1300-65, and 3xxx prior to 1.10.2(42), and 500-32, 1300-47, TX1310 65, and TX9xxx prior to 6.0.4(11), allows remote malicious users to execute arbitrary commands or cause a denial of service (stack memory corruption) via a crafted XML-RPC message, aka Bug ID CSCui32796.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco telepresence system software

cisco telepresence system software 1.5.10(3648)

cisco telepresence system software 1.7.5(42)

cisco telepresence system software 1.7.6(4)

cisco telepresence system software 1.8.0(55)

cisco telepresence system software 1.8.1(34)

cisco telepresence system software 1.8.2(11)

cisco telepresence system software 1.8.3(4)

cisco telepresence system software 1.8.4(13)

cisco telepresence system software 1.8.5(4)

cisco telepresence system software 1.9.0(46)

cisco telepresence system software 1.9.1(68)

cisco telepresence system software 1.9.2(19)

cisco telepresence system software 1.9.3(44)

cisco telepresence system software 1.9.4(19)

cisco telepresence system software 1.9.5(7)

cisco telepresence system software 1.9.6(2)

cisco telepresence system software 1.9.6.1(3)

cisco telepresence system software 1.10.0

cisco telepresence system software 1.10.0(259)

cisco telepresence system software 1.10.1

cisco telepresence system 1000 -

cisco telepresence system 1300-65 -

cisco telepresence system 3000

cisco telepresence system 3010

cisco telepresence system 3200

cisco telepresence system 3210

cisco telepresence system 500-37 -

cisco telepresence system software 6.0.0.1(4)

cisco telepresence system software 6.0.1(50)

cisco telepresence system software 6.0.2(28)

cisco telepresence system software 6.1.0(90)

cisco telepresence system 1100 -

cisco telepresence system 500-32 -

cisco telepresence system tx1300 47

cisco telepresence system tx1310 65

cisco telepresence system tx9000

cisco telepresence system tx9200

Vendor Advisories

Cisco TelePresence System Software contains a vulnerability in the System Status Collection Daemon (SSCD) code that could allow an unauthenticated, adjacent attacker to execute arbitrary commands with the privileges of the root user Cisco has released software updates that address this vulnerability No workarounds that mitigate this vulnerabilit ...