HIGH · 9.0

CVE-2011-2543

Buffer overflow in the cuil component in Cisco Telepresence System Integrator C Series 4.x before TC4.2.0 allows remote authenticated users to cause a denial of service (endpoint reboot or process cra...

Vulnerability Description

Buffer overflow in the cuil component in Cisco Telepresence System Integrator C Series 4.x before TC4.2.0 allows remote authenticated users to cause a denial of service (endpoint reboot or process crash) or possibly execute arbitrary code via a long location parameter to the getxml program, aka Bug ID CSCtq46496.

CVSS Score

9.0

HIGH

AV:N/AC:L/Au:S/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoTelepresence Codec C40All versions
CiscoTelepresence Codec C60All versions
CiscoTelepresence Codec C90All versions
CiscoTelepresence C Series Softwaretc4.0.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-2543?

CVE-2011-2543 is a vulnerability with a CVSS score of 9.0 (HIGH). Buffer overflow in the cuil component in Cisco Telepresence System Integrator C Series 4.x before TC4.2.0 allows remote authenticated users to cause a denial of service (endpoint reboot or process cra...

How severe is CVE-2011-2543?

CVE-2011-2543 has been rated HIGH with a CVSS base score of 9.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-2543?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Telepresence Codec C40, Cisco Telepresence Codec C60, Cisco Telepresence Codec C90, Cisco Telepresence C Series Software.