HIGH · 9.0

CVE-2011-0374

The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "com...

Vulnerability Description

The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCtb31659.

CVSS Score

9.0

HIGH

AV:N/AC:L/Au:S/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoTelepresence System Software1.2.3
CiscoTelepresence System 1000All versions
CiscoTelepresence System 1100All versions
CiscoTelepresence System 3000All versions
CiscoTelepresence System 1300 SeriesAll versions
CiscoTelepresence System 3200 SeriesAll versions
CiscoTelepresence System 500 SeriesAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-0374?

CVE-2011-0374 is a vulnerability with a CVSS score of 9.0 (HIGH). The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "com...

How severe is CVE-2011-0374?

CVE-2011-0374 has been rated HIGH with a CVSS base score of 9.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-0374?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Telepresence System Software, Cisco Telepresence System 1000, Cisco Telepresence System 1100, Cisco Telepresence System 3000, Cisco Telepresence System 1300 Series.