HIGH · 8.3

CVE-2012-2486

The Cisco Discovery Protocol (CDP) implementation on Cisco TelePresence Multipoint Switch before 1.9.0, Cisco TelePresence Immersive Endpoint Devices before 1.9.1, Cisco TelePresence Manager before 1....

Vulnerability Description

The Cisco Discovery Protocol (CDP) implementation on Cisco TelePresence Multipoint Switch before 1.9.0, Cisco TelePresence Immersive Endpoint Devices before 1.9.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server before 1.8.1 allows remote attackers to execute arbitrary code by leveraging certain adjacency and sending a malformed CDP packet, aka Bug IDs CSCtz40953, CSCtz40947, CSCtz40965, and CSCtz40953.

CVSS Score

8.3

HIGH

AV:A/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoTelepresence Multipoint Switch Software<= 1.8.3\(9\)
CiscoTelepresence Multipoint SwitchAll versions
CiscoTelepresence System Software<= 1.9.0.1\(3\)
CiscoTelepresence System 1300 65All versions
CiscoTelepresence System 3000All versions
CiscoTelepresence System 3010All versions
CiscoTelepresence System 3200All versions
CiscoTelepresence System 3210All versions
CiscoTelepresence System T3All versions
CiscoTelepresence System Tx1300 47All versions
CiscoTelepresence System Tx1310 65All versions
CiscoTelepresence System Tx9000All versions
CiscoTelepresence System Tx9200All versions
CiscoTelepresence Manager<= 1.8.1\(682\)
CiscoTelepresence Recording Server<= 1.8.0\(160\)

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-2486?

CVE-2012-2486 is a vulnerability with a CVSS score of 8.3 (HIGH). The Cisco Discovery Protocol (CDP) implementation on Cisco TelePresence Multipoint Switch before 1.9.0, Cisco TelePresence Immersive Endpoint Devices before 1.9.1, Cisco TelePresence Manager before 1....

How severe is CVE-2012-2486?

CVE-2012-2486 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-2486?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Telepresence Multipoint Switch Software, Cisco Telepresence Multipoint Switch, Cisco Telepresence System Software, Cisco Telepresence System 1300 65, Cisco Telepresence System 3000.