CVE-2011-0377: High severity cisco telepresence system software vulnerability
Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x allow remote attackers to cause a denial of service (service crash) via a malformed SOAP request in conjunction with a spoofed TelePresence Manager that supplies an invalid IP address, aka Bug ID CSCth03605.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0377?
CVE-2011-0377 is considered a high severity vulnerability as it allows remote attackers to crash Cisco TelePresence endpoint devices.
How do I fix CVE-2011-0377?
To mitigate CVE-2011-0377, update affected Cisco TelePresence system software to a version later than 1.6.8.
What systems are affected by CVE-2011-0377?
CVE-2011-0377 affects Cisco TelePresence endpoint devices running software versions 1.2.x through 1.6.x.
Is CVE-2011-0377 a denial of service vulnerability?
Yes, CVE-2011-0377 is a denial of service vulnerability that can cause the service to crash.
What type of attack is used in CVE-2011-0377?
CVE-2011-0377 involves a malformed SOAP request in conjunction with a spoofed TelePresence Manager.