CVE-2011-0392: High severity cisco telepresence recording server vulnerability
Cisco TelePresence Recording Server devices with software 1.6.x do not require authentication for an XML-RPC interface, which allows remote attackers to perform unspecified actions via a session on TCP port 8080, aka Bug ID CSCtg35833.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0392?
CVE-2011-0392 is considered a critical vulnerability due to the lack of authentication allowing remote access to sensitive actions.
How do I fix CVE-2011-0392?
To mitigate CVE-2011-0392, upgrade to Cisco TelePresence Recording Server software version 1.6.4 or later, which addresses this vulnerability.
Which devices are affected by CVE-2011-0392?
CVE-2011-0392 affects Cisco TelePresence Recording Server software versions 1.6.1, 1.6.2, and 1.6.3.
What kind of attacks can be conducted due to CVE-2011-0392?
Exploitation of CVE-2011-0392 could allow unauthorized remote attackers to perform unspecified actions via the XML-RPC interface.
Is authentication required for CVE-2011-0392?
No, CVE-2011-0392 does not require authentication, making it more vulnerable to unauthorized access.