First published: Thu Jul 12 2012(Updated: )
The administrative web interface on Cisco TelePresence Immersive Endpoint Devices before 1.7.4 allows remote authenticated users to execute arbitrary commands via a malformed request on TCP port 443, aka Bug ID CSCtn99724.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco TelePresence System Software | <=1.7.2\(4937\) | |
Cisco TelePresence System Software | =1.2.3\(1101\) | |
Cisco TelePresence System Software | =1.3.2\(1393\) | |
Cisco TelePresence System Software | =1.4.7\(2229\) | |
Cisco TelePresence System Software | =1.5.1\(2082\) | |
Cisco TelePresence System Software | =1.5.3\(2115\) | |
Cisco TelePresence System Software | =1.5.10\(3648\) | |
Cisco TelePresence System Software | =1.5.11\(3659\) | |
Cisco TelePresence System Software | =1.5.12\(3701\) | |
Cisco TelePresence System Software | =1.5.13\(3717\) | |
Cisco TelePresence System Software | =1.6.0\(3954\) | |
Cisco TelePresence System Software | =1.6.2\(4023\) | |
Cisco TelePresence System Software | =1.6.3\(4042\) | |
Cisco TelePresence System Software | =1.6.4\(4072\) | |
Cisco TelePresence System Software | =1.6.5\(4097\) | |
Cisco TelePresence System Software | =1.6.6\(4109\) | |
Cisco TelePresence System Software | =1.6.7\(4212\) | |
Cisco TelePresence System Software | =1.6.8\(4222\) | |
Cisco TelePresence System Software | =1.7.0.1\(4764\) | |
Cisco TelePresence System Software | =1.7.0.2\(4719\) | |
Cisco TelePresence System Software | =1.7.1\(4864\) | |
Cisco TelePresence System Software | =1.7.2.1\(2\) | |
Cisco TelePresence system 1300 | ||
Cisco TelePresence System 3000 | ||
Cisco TelePresence System 3010 | ||
Cisco TelePresence System 3200 series | ||
Cisco TelePresence System 3210 | ||
Cisco TelePresence System | ||
Cisco TelePresence System | ||
Cisco TelePresence System 1300 | ||
Cisco TelePresence System TX1310 65 | ||
Cisco Telepresence Tx9000 Firmware | ||
Cisco TelePresence System tx9200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3075 has been classified with a high severity level due to the potential for remote command execution by authenticated users.
To fix CVE-2012-3075, upgrade your Cisco TelePresence Immersive Endpoint Devices to version 1.7.4 or later.
CVE-2012-3075 affects various models of Cisco TelePresence System Software, specifically those before version 1.7.4.
Yes, CVE-2012-3075 allows remote authenticated users to exploit the vulnerability through a malformed request.
The impact of CVE-2012-3075 is that remote authenticated attackers can execute arbitrary commands on the affected Cisco TelePresence devices.