CVE-2014-2173: High severity Cisco Telepresence Te Software vulnerability
Published May 2, 2014
·Updated
Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 do not properly restrict access to the serial port, which allows local users to gain privileges via unspecified commands, aka Bug ID CSCub67692.
Affected Software
26 affected components
Cisco Telepresence Te Software=4.1.0
Cisco Telepresence Te Software=4.1.1
Cisco Telepresence Te Software=4.1.2
Cisco Telepresence Te Software=4.1.3
Cisco Telepresence Te Software=6.0
Cisco TelePresence TC Software=4.0.0
Cisco TelePresence TC Software=4.0.1
Cisco TelePresence TC Software=4.0.4
Cisco TelePresence TC Software=4.1.1
Cisco TelePresence TC Software=4.1.2
Cisco TelePresence TC Software=4.2.0
Cisco TelePresence TC Software=4.2.1
Cisco TelePresence TC Software=4.2.2
Cisco TelePresence TC Software=4.2.3
Cisco TelePresence TC Software=4.2.4
Cisco TelePresence TC Software=5.0.0
Cisco TelePresence TC Software=5.0.1
Cisco TelePresence TC Software=5.0.2
Cisco TelePresence TC Software=5.1.0
Cisco TelePresence TC Software=5.1.1
Cisco TelePresence TC Software=5.1.2
Cisco TelePresence TC Software=5.1.3
Cisco TelePresence TC Software=5.1.4
Cisco TelePresence TC Software=5.1.5
Cisco TelePresence TC Software=5.1.6
Cisco TelePresence TC Software=5.1.7
Event History
May 2, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:55 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2173?
CVE-2014-2173 has a CVSS score that categorizes it as a high-severity vulnerability.
2
How do I fix CVE-2014-2173?
To remediate CVE-2014-2173, update your Cisco TelePresence TC Software or TE Software to the latest version provided by Cisco.
3
What are the affected versions in CVE-2014-2173?
CVE-2014-2173 affects Cisco TelePresence TC Software versions 4.x, 5.x and TE Software versions 4.x, 6.0.
4
Is CVE-2014-2173 a local or remote vulnerability?
CVE-2014-2173 is a local vulnerability that requires an authenticated user to exploit it.
5
What type of access does CVE-2014-2173 allow?
CVE-2014-2173 allows local users to gain elevated privileges through unspecified commands.