CVE-2012-3075: OS Command Injection
The administrative web interface on Cisco TelePresence Immersive Endpoint Devices before 1.7.4 allows remote authenticated users to execute arbitrary commands via a malformed request on TCP port 443, aka Bug ID CSCtn99724.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3075?
CVE-2012-3075 has been classified with a high severity level due to the potential for remote command execution by authenticated users.
How do I fix CVE-2012-3075?
To fix CVE-2012-3075, upgrade your Cisco TelePresence Immersive Endpoint Devices to version 1.7.4 or later.
What types of devices are affected by CVE-2012-3075?
CVE-2012-3075 affects various models of Cisco TelePresence System Software, specifically those before version 1.7.4.
Is CVE-2012-3075 remotely exploitable?
Yes, CVE-2012-3075 allows remote authenticated users to exploit the vulnerability through a malformed request.
What is the impact of CVE-2012-3075 on Cisco devices?
The impact of CVE-2012-3075 is that remote authenticated attackers can execute arbitrary commands on the affected Cisco TelePresence devices.