CVE-2011-0386: Code Injection
The XML-RPC implementation on Cisco TelePresence Recording Server devices with software 1.6.x and 1.7.x before 1.7.1 allows remote attackers to overwrite files and consequently execute arbitrary code via a malformed request, aka Bug ID CSCti50739.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0386?
CVE-2011-0386 is classified as a high-severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2011-0386?
To fix CVE-2011-0386, upgrade the Cisco TelePresence Recording Server software to version 1.7.1 or later.
What devices are affected by CVE-2011-0386?
CVE-2011-0386 affects Cisco TelePresence Recording Server devices running versions 1.6.x and 1.7.x prior to 1.7.1.
Can CVE-2011-0386 be exploited remotely?
Yes, CVE-2011-0386 can be exploited remotely by attackers through malformed XML-RPC requests.
What type of attack does CVE-2011-0386 enable?
CVE-2011-0386 enables attackers to overwrite files and execute arbitrary code on the vulnerable device.