CVE-2011-0378: OS Command Injection
The XML-RPC implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a TCP request, related to a "command injection vulnerability," aka Bug ID CSCtb52587.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0378?
CVE-2011-0378 is rated as a high severity vulnerability due to its potential to allow remote command execution.
How do I fix CVE-2011-0378?
To fix CVE-2011-0378, update the affected Cisco TelePresence software to a version that is not vulnerable, as indicated by Cisco's advisory.
What systems are affected by CVE-2011-0378?
CVE-2011-0378 affects Cisco TelePresence endpoint devices running software versions 1.2.x through 1.5.x.
What type of vulnerability is CVE-2011-0378?
CVE-2011-0378 is a command injection vulnerability that allows remote attackers to execute arbitrary commands.
What are the consequences of exploiting CVE-2011-0378?
Exploitation of CVE-2011-0378 may lead to unauthorized access and complete control over the affected TelePresence systems.