HIGH · 8.3

CVE-2012-3074

An unspecified API on Cisco TelePresence Immersive Endpoint Devices before 1.9.1 allows remote attackers to execute arbitrary commands by leveraging certain adjacency and sending a malformed request o...

Vulnerability Description

An unspecified API on Cisco TelePresence Immersive Endpoint Devices before 1.9.1 allows remote attackers to execute arbitrary commands by leveraging certain adjacency and sending a malformed request on TCP port 61460, aka Bug ID CSCtz38382.

CVSS Score

8.3

HIGH

AV:A/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoTelepresence System Software<= 1.9.0.1\(3\)
CiscoTelepresence System 1300 65All versions
CiscoTelepresence System 3000All versions
CiscoTelepresence System 3010All versions
CiscoTelepresence System 3200All versions
CiscoTelepresence System 3210All versions
CiscoTelepresence System T3All versions
CiscoTelepresence System Tx1300 47All versions
CiscoTelepresence System Tx1310 65All versions
CiscoTelepresence System Tx9000All versions
CiscoTelepresence System Tx9200All versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-3074?

CVE-2012-3074 is a vulnerability with a CVSS score of 8.3 (HIGH). An unspecified API on Cisco TelePresence Immersive Endpoint Devices before 1.9.1 allows remote attackers to execute arbitrary commands by leveraging certain adjacency and sending a malformed request o...

How severe is CVE-2012-3074?

CVE-2012-3074 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-3074?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Telepresence System Software, Cisco Telepresence System 1300 65, Cisco Telepresence System 3000, Cisco Telepresence System 3010, Cisco Telepresence System 3200.