LOW · 3.5

CVE-2011-2544

Cross-site scripting (XSS) vulnerability in the web interface in Cisco TelePresence System MXP Series F9.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via a cr...

Vulnerability Description

Cross-site scripting (XSS) vulnerability in the web interface in Cisco TelePresence System MXP Series F9.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via a crafted Call ID, as demonstrated by resultant cross-site request forgery (CSRF) attacks that change passwords or cause a denial of service, aka Bug ID CSCtq46488.

CVSS Score

3.5

LOW

AV:N/AC:M/Au:S/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
CiscoTelepresence System 1000 MxpAll versions
CiscoTelepresence System 1700 MxpAll versions
CiscoTelepresence Mxp Software<= f9.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-2544?

CVE-2011-2544 is a vulnerability with a CVSS score of 3.5 (LOW). Cross-site scripting (XSS) vulnerability in the web interface in Cisco TelePresence System MXP Series F9.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via a cr...

How severe is CVE-2011-2544?

CVE-2011-2544 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-2544?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Telepresence System 1000 Mxp, Cisco Telepresence System 1700 Mxp, Cisco Telepresence Mxp Software.