CVE-2011-0374: OS Command Injection
The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCtb31659.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0374?
CVE-2011-0374 has a high severity rating due to its potential for command injection leading to remote execution.
How do I fix CVE-2011-0374?
To fix CVE-2011-0374, upgrade to the latest version of Cisco TelePresence Software that is not affected by this vulnerability.
Who is affected by CVE-2011-0374?
CVE-2011-0374 affects Cisco TelePresence endpoint devices running vulnerable versions of software 1.2.x to 1.5.x.
What are the potential risks of CVE-2011-0374?
The risks of CVE-2011-0374 include unauthorized command execution by remote authenticated users, which can compromise device security.
Is CVE-2011-0374 being actively exploited?
At the time of disclosure, there were no known active exploitation reports for CVE-2011-0374, but users are advised to secure their devices.