CVE-2011-2544: XSS
Cross-site scripting (XSS) vulnerability in the web interface in Cisco TelePresence System MXP Series F9.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via a crafted Call ID, as demonstrated by resultant cross-site request forgery (CSRF) attacks that change passwords or cause a denial of service, aka Bug ID CSCtq46488.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2544?
CVE-2011-2544 has a medium severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2011-2544?
To fix CVE-2011-2544, upgrade to the latest version of the Cisco TelePresence software that addresses this vulnerability.
Who is affected by CVE-2011-2544?
CVE-2011-2544 affects users of Cisco TelePresence System MXP Series F9.1 and earlier and certain affected models.
What type of attack is associated with CVE-2011-2544?
CVE-2011-2544 is associated with cross-site scripting (XSS) attacks allowing script injection.
Is authentication required to exploit CVE-2011-2544?
Yes, an attacker must be an authenticated user to exploit the XSS vulnerability in CVE-2011-2544.