First published: Wed Jul 10 2013(Updated: )
The web portal in TC software on Cisco TelePresence endpoints does not require an exact password match during a login attempt by a user who has not configured a password, which allows remote attackers to bypass authentication by sending an arbitrary password, aka Bug ID CSCud96071.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco TelePresence TC |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3405 is classified as a high severity vulnerability due to the potential for unauthorized access to Cisco TelePresence endpoints.
To fix CVE-2013-3405, configure a strong password for the user accounts on affected Cisco TelePresence endpoints.
CVE-2013-3405 affects the web portal of Cisco TelePresence TC software.
CVE-2013-3405 is vulnerable to remote authentication bypass attacks.
Yes, CVE-2013-3405 can be exploited remotely without requiring physical access to the device.