HIGH · 10.0

CVE-2011-0372

The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a malformed request, related to "command injec...

Vulnerability Description

The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCtb31640.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoTelepresence System Software1.2.3
CiscoTelepresence System 1000All versions
CiscoTelepresence System 1100All versions
CiscoTelepresence System 3000All versions
CiscoTelepresence System 1300 SeriesAll versions
CiscoTelepresence System 3200 SeriesAll versions
CiscoTelepresence System 500 SeriesAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-0372?

CVE-2011-0372 is a vulnerability with a CVSS score of 10.0 (HIGH). The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a malformed request, related to "command injec...

How severe is CVE-2011-0372?

CVE-2011-0372 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-0372?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Telepresence System Software, Cisco Telepresence System 1000, Cisco Telepresence System 1100, Cisco Telepresence System 3000, Cisco Telepresence System 1300 Series.