First published: Thu Jul 12 2012(Updated: )
The administrative web interface on Cisco TelePresence Recording Server before 1.8.0 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Bug ID CSCth85804.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco TelePresence Recording Server software | <=1.7.3\(3\) | |
Cisco TelePresence Recording Server software | =1.6.1\(2\) | |
Cisco TelePresence Recording Server software | =1.6.2\(31\) | |
Cisco TelePresence Recording Server software | =1.6.3\(4\) | |
Cisco TelePresence Recording Server software | =1.7.0\(190\) | |
Cisco TelePresence Recording Server software | =1.7.1\(22\) | |
Cisco TelePresence Recording Server software | =1.7.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3076 is classified with a medium severity level due to the potential for arbitrary command execution by remote authenticated users.
To mitigate CVE-2012-3076, upgrade the Cisco TelePresence Recording Server to version 1.8.0 or later.
CVE-2012-3076 affects several versions of Cisco TelePresence Recording Server including versions prior to 1.8.0.
No, CVE-2012-3076 requires remote authenticated users to exploit the vulnerability.
Exploitation of CVE-2012-3076 could allow an authenticated attacker to execute arbitrary commands on the Cisco TelePresence Recording Server.