HIGH · 8.3

CVE-2011-0378

The XML-RPC implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a TCP request, related to a "command injec...

Vulnerability Description

The XML-RPC implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a TCP request, related to a "command injection vulnerability," aka Bug ID CSCtb52587.

CVSS Score

8.3

HIGH

AV:A/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoTelepresence System Software1.2.3
CiscoTelepresence System 1000All versions
CiscoTelepresence System 1100All versions
CiscoTelepresence System 3000All versions
CiscoTelepresence System 1300 SeriesAll versions
CiscoTelepresence System 3200 SeriesAll versions
CiscoTelepresence System 500 SeriesAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-0378?

CVE-2011-0378 is a vulnerability with a CVSS score of 8.3 (HIGH). The XML-RPC implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a TCP request, related to a "command injec...

How severe is CVE-2011-0378?

CVE-2011-0378 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-0378?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Telepresence System Software, Cisco Telepresence System 1000, Cisco Telepresence System 1100, Cisco Telepresence System 3000, Cisco Telepresence System 1300 Series.