CVE-2013-3454: Critical severity cisco telepresence tx9000 firmware vulnerability

Published Aug 8, 2013
·
Updated

Cisco TelePresence System Software 1.10.1 and earlier on 500, 13X0, 1X00, 30X0, and 3X00 devices, and 6.0.3 and earlier on TX 9X00 devices, has a default password for the pwrecovery account, which makes it easier for remote attackers to modify the configuration or perform arbitrary actions via HTTPS requests, aka Bug ID CSCui43128.

Affected Software

76 affected components
Cisco Telepresence System Tx9000
Cisco Telepresence System Tx9200
Cisco TelePresence System Software<=6.0.3\(33\)
Cisco TelePresence System Software=1.9.0\(46\)
Cisco TelePresence System Software=1.9.0.1\(3\)
Cisco TelePresence System Software=1.9.1\(68\)
Cisco TelePresence System Software=1.9.2
Cisco TelePresence System Software=1.9.2\(19\)
Cisco TelePresence System Software=1.9.3
Cisco TelePresence System Software=1.9.3\(44\)
Cisco TelePresence System Software=1.9.4
Cisco TelePresence System Software=1.9.4\(19\)
Cisco TelePresence System Software=1.9.5
Cisco TelePresence System Software=1.9.5\(7\)
Cisco TelePresence System Software=1.9.6
Cisco TelePresence System Software=1.9.6\(2\)
Cisco TelePresence System Software=6.0.0.1\(4\)
Cisco TelePresence System Software=6.0.1\(50\)
Cisco TelePresence System Software=6.0.2\(28\)
Cisco TelePresence System Software<=1.10.1
Cisco TelePresence System Software=1.2.3
Cisco TelePresence System Software=1.2.3\(1101\)
Cisco TelePresence System Software=1.3.2
Cisco TelePresence System Software=1.3.2\(1393\)
Cisco TelePresence System Software=1.4.7
Cisco TelePresence System Software=1.4.7\(2229\)
Cisco TelePresence System Software=1.5.1
Cisco TelePresence System Software=1.5.1\(2082\)
Cisco TelePresence System Software=1.5.3
Cisco TelePresence System Software=1.5.3\(2115\)
Cisco TelePresence System Software=1.5.10
Cisco TelePresence System Software=1.5.10\(3648\)
Cisco TelePresence System Software=1.5.11
Cisco TelePresence System Software=1.5.11\(3659\)
Cisco TelePresence System Software=1.5.12
Cisco TelePresence System Software=1.5.12\(3701\)
Cisco TelePresence System Software=1.5.13
Cisco TelePresence System Software=1.5.13\(3717\)
Cisco TelePresence System Software=1.6.0
Cisco TelePresence System Software=1.6.0\(3954\)
Cisco TelePresence System Software=1.6.1
Cisco TelePresence System Software=1.6.2
Cisco TelePresence System Software=1.6.2\(4023\)
Cisco TelePresence System Software=1.6.3
Cisco TelePresence System Software=1.6.3\(4042\)
Cisco TelePresence System Software=1.6.4
Cisco TelePresence System Software=1.6.4\(4072\)
Cisco TelePresence System Software=1.6.5
Cisco TelePresence System Software=1.6.5\(4097\)
Cisco TelePresence System Software=1.6.6
Cisco TelePresence System Software=1.6.6\(4109\)
Cisco TelePresence System Software=1.6.7
Cisco TelePresence System Software=1.6.7\(4212\)
Cisco TelePresence System Software=1.6.8
Cisco TelePresence System Software=1.6.8\(4222\)
Cisco TelePresence System Software=1.7.0.1\(4764\)
Cisco TelePresence System Software=1.7.0.2\(4719\)
Cisco TelePresence System Software=1.7.1\(4864\)
Cisco TelePresence System Software=1.7.2\(4937\)
Cisco TelePresence System Software=1.7.2.1\(2\)
Cisco TelePresence System Software=1.7.4\(270\)
Cisco TelePresence System Software=1.7.5\(42\)
Cisco TelePresence System Software=1.7.6\(4\)
Cisco TelePresence System Software=1.8.0\(55\)
Cisco TelePresence System Software=1.8.1\(34\)
Cisco TelePresence System Software=1.8.2\(11\)
Cisco TelePresence System Software=1.8.3\(4\)
Cisco TelePresence System Software=1.10.0
Cisco Telepresence System 1300
Cisco Telepresence System 1300-65
Cisco Telepresence System 3000
Cisco Telepresence System 3010
Cisco Telepresence System 3200
Cisco Telepresence System 3210
Cisco Telepresence System 500-32
Cisco TelePresence System 500-37

Event History

Aug 8, 2013
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2013-3454?

CVE-2013-3454 has a high severity rating due to the risk of unauthorized access through a default password.

2

How do I fix CVE-2013-3454?

To fix CVE-2013-3454, change the default password for the pwrecovery account immediately.

3

Which Cisco products are affected by CVE-2013-3454?

CVE-2013-3454 affects multiple Cisco TelePresence System Software versions 1.10.1 and earlier, as well as 6.0.3 and earlier on certain devices.

4

What are the potential impacts of CVE-2013-3454 exploitation?

Exploitation of CVE-2013-3454 could allow remote attackers to modify configurations or perform arbitrary actions.

5

Is there a CISCO patch available for CVE-2013-3454?

Yes, Cisco has released patches to address CVE-2013-3454, which should be applied to vulnerable systems.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203