First published: Fri Feb 25 2011(Updated: )
The XML-RPC implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a TCP request, related to a "command injection vulnerability," aka Bug ID CSCtb52587.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco TelePresence System Software | =1.2.3 | |
Cisco TelePresence System Software | =1.3.2 | |
Cisco TelePresence System Software | =1.4.7 | |
Cisco TelePresence System Software | =1.5.1 | |
Cisco TelePresence System Software | =1.5.3 | |
Cisco TelePresence System Software | =1.5.10 | |
Cisco TelePresence System Software | =1.5.11 | |
Cisco TelePresence System Software | =1.5.12 | |
Cisco TelePresence System Software | =1.5.13 | |
Cisco TelePresence System 1000 MXP | ||
Cisco TelePresence System 1100 | ||
Cisco TelePresence System 3000 | ||
Cisco TelePresence System 1300 | ||
Cisco TelePresence System Software | =1.4.7 | |
Cisco TelePresence System Software | =1.5.1 | |
Cisco TelePresence System Software | =1.5.3 | |
Cisco TelePresence System Software | =1.5.10 | |
Cisco TelePresence System Software | =1.5.11 | |
Cisco TelePresence System Software | =1.5.12 | |
Cisco TelePresence System Software | =1.5.13 | |
Cisco TelePresence System 3200 | ||
Cisco TelePresence System 500 Series |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0378 is rated as a high severity vulnerability due to its potential to allow remote command execution.
To fix CVE-2011-0378, update the affected Cisco TelePresence software to a version that is not vulnerable, as indicated by Cisco's advisory.
CVE-2011-0378 affects Cisco TelePresence endpoint devices running software versions 1.2.x through 1.5.x.
CVE-2011-0378 is a command injection vulnerability that allows remote attackers to execute arbitrary commands.
Exploitation of CVE-2011-0378 may lead to unauthorized access and complete control over the affected TelePresence systems.