CVE-2014-2172: Buffer Overflow
Published May 2, 2014
·Updated
Buffer overflow in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows local users to gain privileges by leveraging improper handling of the u-boot compiler flag for internal executable files, aka Bug ID CSCub67693.
Affected Software
26 affected components
Cisco TelePresence TC Software=4.0.0
Cisco TelePresence TC Software=4.0.1
Cisco TelePresence TC Software=4.0.4
Cisco TelePresence TC Software=4.1.1
Cisco TelePresence TC Software=4.1.2
Cisco TelePresence TC Software=4.2.0
Cisco TelePresence TC Software=4.2.1
Cisco TelePresence TC Software=4.2.2
Cisco TelePresence TC Software=4.2.3
Cisco TelePresence TC Software=4.2.4
Cisco TelePresence TC Software=5.0.0
Cisco TelePresence TC Software=5.0.1
Cisco TelePresence TC Software=5.0.2
Cisco TelePresence TC Software=5.1.0
Cisco TelePresence TC Software=5.1.1
Cisco TelePresence TC Software=5.1.2
Cisco TelePresence TC Software=5.1.3
Cisco TelePresence TC Software=5.1.4
Cisco TelePresence TC Software=5.1.5
Cisco TelePresence TC Software=5.1.6
Cisco TelePresence TC Software=5.1.7
Cisco Telepresence Te Software=4.1.0
Cisco Telepresence Te Software=4.1.1
Cisco Telepresence Te Software=4.1.2
Cisco Telepresence Te Software=4.1.3
Cisco Telepresence Te Software=6.0
Event History
May 2, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:55 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2172?
The severity of CVE-2014-2172 is classified as high due to the potential for local privilege escalation.
2
How do I fix CVE-2014-2172?
To fix CVE-2014-2172, upgrade Cisco TelePresence TC Software to version 5.1.4 or later.
3
Which Cisco products are affected by CVE-2014-2172?
CVE-2014-2172 affects Cisco TelePresence TC Software versions 4.x and 5.x, as well as TE Software versions 4.x and 6.0.
4
Can CVE-2014-2172 be exploited remotely?
No, CVE-2014-2172 requires local access to the affected Cisco devices for exploitation.
5
What type of vulnerability is CVE-2014-2172?
CVE-2014-2172 is a buffer overflow vulnerability that affects the handling of internal executable files.