First published: Thu Jul 12 2012(Updated: )
An unspecified API on Cisco TelePresence Immersive Endpoint Devices before 1.9.1 allows remote attackers to execute arbitrary commands by leveraging certain adjacency and sending a malformed request on TCP port 61460, aka Bug ID CSCtz38382.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco TelePresence System Software | <=1.9.0.1\(3\) | |
Cisco TelePresence System Software | =1.2.3\(1101\) | |
Cisco TelePresence System Software | =1.3.2\(1393\) | |
Cisco TelePresence System Software | =1.4.7\(2229\) | |
Cisco TelePresence System Software | =1.5.1\(2082\) | |
Cisco TelePresence System Software | =1.5.3\(2115\) | |
Cisco TelePresence System Software | =1.5.10\(3648\) | |
Cisco TelePresence System Software | =1.5.11\(3659\) | |
Cisco TelePresence System Software | =1.5.12\(3701\) | |
Cisco TelePresence System Software | =1.5.13\(3717\) | |
Cisco TelePresence System Software | =1.6.0\(3954\) | |
Cisco TelePresence System Software | =1.6.2\(4023\) | |
Cisco TelePresence System Software | =1.6.3\(4042\) | |
Cisco TelePresence System Software | =1.6.4\(4072\) | |
Cisco TelePresence System Software | =1.6.5\(4097\) | |
Cisco TelePresence System Software | =1.6.6\(4109\) | |
Cisco TelePresence System Software | =1.6.7\(4212\) | |
Cisco TelePresence System Software | =1.6.8\(4222\) | |
Cisco TelePresence System Software | =1.7.0.1\(4764\) | |
Cisco TelePresence System Software | =1.7.0.2\(4719\) | |
Cisco TelePresence System Software | =1.7.1\(4864\) | |
Cisco TelePresence System Software | =1.7.2\(4937\) | |
Cisco TelePresence System Software | =1.7.2.1\(2\) | |
Cisco TelePresence System Software | =1.7.4\(270\) | |
Cisco TelePresence System Software | =1.7.5\(42\) | |
Cisco TelePresence System Software | =1.7.6\(4\) | |
Cisco TelePresence System Software | =1.8.0\(55\) | |
Cisco TelePresence System Software | =1.8.1\(34\) | |
Cisco TelePresence System Software | =1.8.2\(11\) | |
Cisco TelePresence System Software | =1.8.3\(4\) | |
Cisco TelePresence System Software | =1.9.0\(46\) | |
Cisco TelePresence system 1300 | ||
Cisco TelePresence System 3000 | ||
Cisco TelePresence System 3010 | ||
Cisco TelePresence System 3200 series | ||
Cisco TelePresence System 3210 | ||
Cisco TelePresence System | ||
Cisco TelePresence System | ||
Cisco TelePresence System 1300 | ||
Cisco TelePresence System TX1310 65 | ||
Cisco Telepresence Tx9000 Firmware | ||
Cisco TelePresence System tx9200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3074 is rated as a critical vulnerability due to the potential for remote code execution.
To remediate CVE-2012-3074, upgrade the affected Cisco TelePresence system to a version that is 1.9.1 or higher.
CVE-2012-3074 affects multiple versions of Cisco TelePresence System Software prior to version 1.9.1.
Yes, CVE-2012-3074 can lead to unauthorized command execution which may compromise data integrity.
There is no documented workaround for CVE-2012-3074; the only solution is to update to the patched software version.