HIGH · 7.8

CVE-2012-3073

The IP implementation on Cisco TelePresence Multipoint Switch before 1.8.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server 1.8 and earlier allows remote attackers to ...

Vulnerability Description

The IP implementation on Cisco TelePresence Multipoint Switch before 1.8.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server 1.8 and earlier allows remote attackers to cause a denial of service (networking outage or process crash) via (1) malformed IP packets, (2) a high rate of TCP connection requests, or (3) a high rate of TCP connection terminations, aka Bug IDs CSCti21830, CSCti21851, CSCtj19100, CSCtj19086, CSCtj19078, CSCty11219, CSCty11299, CSCty11323, and CSCty11338.

CVSS Score

7.8

HIGH

AV:N/AC:L/Au:N/C:N/I:N/A:C
Confidentiality
NONE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoTelepresence Multipoint Switch Software<= 1.8.0\(1026\)
CiscoTelepresence Multipoint SwitchAll versions
CiscoTelepresence System Software<= 1.9.0.1\(3\)
CiscoTelepresence System 1300 65All versions
CiscoTelepresence System 3000All versions
CiscoTelepresence System 3010All versions
CiscoTelepresence System 3200All versions
CiscoTelepresence System 3210All versions
CiscoTelepresence System T3All versions
CiscoTelepresence System Tx1300 47All versions
CiscoTelepresence System Tx1310 65All versions
CiscoTelepresence System Tx9000All versions
CiscoTelepresence System Tx9200All versions
CiscoTelepresence Manager<= 1.8.1\(682\)
CiscoTelepresence Recording Server<= 1.8.0\(160\)

References

FAQ

What is CVE-2012-3073?

CVE-2012-3073 is a vulnerability with a CVSS score of 7.8 (HIGH). The IP implementation on Cisco TelePresence Multipoint Switch before 1.8.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server 1.8 and earlier allows remote attackers to ...

How severe is CVE-2012-3073?

CVE-2012-3073 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-3073?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Telepresence Multipoint Switch Software, Cisco Telepresence Multipoint Switch, Cisco Telepresence System Software, Cisco Telepresence System 1300 65, Cisco Telepresence System 3000.