CVE-2011-4659: Critical severity cisco telepresence e20 vulnerability
Cisco TelePresence Software before TE 4.1.1 on the Cisco IP Video Phone E20 has a default password for the root account after an upgrade to TE 4.1.0, which makes it easier for remote attackers to modify the configuration via an SSH session, aka Bug ID CSCtw69889, a different vulnerability than CVE-2011-2555.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4659?
CVE-2011-4659 is classified as a high severity vulnerability due to the potential for unauthorized access and configuration changes to Cisco TelePresence systems.
How do I fix CVE-2011-4659?
To fix CVE-2011-4659, reset the default root password after upgrading to Cisco TelePresence Software version 4.1.1 or later.
Which Cisco products are affected by CVE-2011-4659?
CVE-2011-4659 affects Cisco TelePresence Software prior to version 4.1.1 on the Cisco IP Video Phone E20.
Can CVE-2011-4659 be exploited remotely?
Yes, CVE-2011-4659 can be exploited remotely, allowing attackers to modify the configuration via an SSH session.
Is there a workaround for CVE-2011-4659?
The recommended workaround for CVE-2011-4659 is to immediately change the default password for the root account on the affected devices.