CVE-2011-0380: High severity cisco telepresence manager vulnerability
Published Feb 25, 2011
·Updated
Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to bypass authentication and invoke arbitrary methods via a malformed SOAP request, aka Bug ID CSCtc59562.
Affected Software
9 affected components
Cisco TelePresence Manager=1.2.0.0
Cisco TelePresence Manager=1.3.2
Cisco TelePresence Manager=1.4.0
Cisco TelePresence Manager=1.5.1
Cisco TelePresence Manager=1.5.2
Cisco TelePresence Manager=1.6.0
Cisco TelePresence Manager=1.6.2
Cisco TelePresence Manager=1.6.3
Cisco TelePresence Manager=1.6.5
Event History
Feb 25, 2011
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-0380?
CVE-2011-0380 is rated as a high severity vulnerability due to its ability to allow remote attackers to bypass authentication.
2
How do I fix CVE-2011-0380?
To fix CVE-2011-0380, upgrade your Cisco TelePresence Manager to a version that is not affected, such as version 1.6.6 or later.
3
What kind of attack does CVE-2011-0380 enable?
CVE-2011-0380 enables remote attackers to invoke arbitrary methods on affected Cisco TelePresence Manager instances.
4
Which versions of Cisco TelePresence Manager are affected by CVE-2011-0380?
CVE-2011-0380 affects Cisco TelePresence Manager versions 1.2.x through 1.6.x.
5
Is authentication required to exploit CVE-2011-0380?
No, CVE-2011-0380 allows attackers to bypass authentication, making it accessible for exploitation without credentials.