7.2
CVSSv2

CVE-2014-2173

Published: 02/05/2014 Updated: 02/05/2014
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Cisco TelePresence TC and TE Software are affected by the following vulnerabilities: Six Session Initiation Protocol (SIP) denial of service vulnerabilities Cisco TelePresence TC and TE Software DNS Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Input Validation Vulnerability Cisco TelePresence TC and TE Software tshell Command Injection Vulnerability Cisco TelePresence TC and TE Software Heap Overflow Vulnerability Cisco TelePresence TC and TE Software U-Boot Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Unauthenticated Serial Port Access Vulnerability Cisco TelePresence TC H.225 Denial of Service Vulnerability Successful exploitation of these vulnerabilities could allow an malicious user to cause the affected system to reload, execute arbitrary commands or obtain privileged access to the affected system. Note: This security advisory does not provide information about the OpenSSL TLS Heartbeat Read Overrun Vulnerability identified by CVE-2014-0160 (also known as Heartbleed). For additional information on Cisco products affected by the Heartbleed vulnerability, refer to the Cisco Security Advisory available at the following link: tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140409-heartbleed Cisco has released software updates that address these vulnerabilities. There are no workarounds that mitigate these vulnerabilities. This advisory is available at the following link: tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140430-tcte

Vulnerable Product Search on Vulmon Subscribe to Product

cisco telepresence te software 4.1.1

cisco telepresence te software 4.1.2

cisco telepresence te software 4.1.3

cisco telepresence te software 4.1.0

cisco telepresence te software 6.0

cisco telepresence tc software 5.1.1

cisco telepresence tc software 5.1.2

cisco telepresence tc software 5.1.3

cisco telepresence tc software 5.1.4

cisco telepresence tc software 4.0.4

cisco telepresence tc software 4.1.1

cisco telepresence tc software 4.1.2

cisco telepresence tc software 4.2.0

cisco telepresence tc software 5.1.7

cisco telepresence tc software 5.0.1

cisco telepresence tc software 5.1.0

cisco telepresence tc software 5.1.5

cisco telepresence tc software 4.0.0

cisco telepresence tc software 4.2.2

cisco telepresence tc software 4.2.4

cisco telepresence tc software 5.0.0

cisco telepresence tc software 5.0.2

cisco telepresence tc software 5.1.6

cisco telepresence tc software 4.0.1

cisco telepresence tc software 4.2.1

cisco telepresence tc software 4.2.3

Vendor Advisories

Cisco TelePresence TC and TE Software are affected by the following vulnerabilities: Six Session Initiation Protocol (SIP) denial of service vulnerabilities Cisco TelePresence TC and TE Software DNS Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Input Validation Vulnerability Cisco TelePresence TC and TE Softwa ...