cisco-sa-20190206-tms-soap: Cisco TelePresence Management Suite Web Services
Cisco TelePresence Management Suite (TMS) software implements a Simple Object Access Protocol (SOAP) interface that by design allows unauthenticated access to web services designed to provide management features to devices. At first publication of the advisory, the management feature was not documented and may have represented unknown risks to customers implementing the feature within their environments. Customers should refer to page 18 of the Cisco TMS Admin Guide for additional information that documents the management feature.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190206-tms-soap
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-20190206-tms-soap?
The severity of cisco-sa-20190206-tms-soap is considered high due to its unauthenticated access vulnerability.
How do I fix cisco-sa-20190206-tms-soap?
To fix cisco-sa-20190206-tms-soap, you should apply the latest security updates provided by Cisco for the TelePresence Management Suite software.
What systems are affected by cisco-sa-20190206-tms-soap?
The affected systems include Cisco TelePresence Management Suite software.
What impact does cisco-sa-20190206-tms-soap have on security?
The impact of cisco-sa-20190206-tms-soap allows attackers to exploit the SOAP interface to gain unauthorized access to management features.
Is authentication required for cisco-sa-20190206-tms-soap?
No, authentication is not required for accessing the SOAP interface in cisco-sa-20190206-tms-soap.