HIGH · 9.0

CVE-2012-3075

The administrative web interface on Cisco TelePresence Immersive Endpoint Devices before 1.7.4 allows remote authenticated users to execute arbitrary commands via a malformed request on TCP port 443, ...

Vulnerability Description

The administrative web interface on Cisco TelePresence Immersive Endpoint Devices before 1.7.4 allows remote authenticated users to execute arbitrary commands via a malformed request on TCP port 443, aka Bug ID CSCtn99724.

CVSS Score

9.0

HIGH

AV:N/AC:L/Au:S/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
CiscoTelepresence System Software<= 1.7.2\(4937\)
CiscoTelepresence System 1300 65All versions
CiscoTelepresence System 3000All versions
CiscoTelepresence System 3010All versions
CiscoTelepresence System 3200All versions
CiscoTelepresence System 3210All versions
CiscoTelepresence System T3All versions
CiscoTelepresence System Tx1300 47All versions
CiscoTelepresence System Tx1310 65All versions
CiscoTelepresence System Tx9000All versions
CiscoTelepresence System Tx9200All versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-3075?

CVE-2012-3075 is a vulnerability with a CVSS score of 9.0 (HIGH). The administrative web interface on Cisco TelePresence Immersive Endpoint Devices before 1.7.4 allows remote authenticated users to execute arbitrary commands via a malformed request on TCP port 443, ...

How severe is CVE-2012-3075?

CVE-2012-3075 has been rated HIGH with a CVSS base score of 9.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-3075?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Telepresence System Software, Cisco Telepresence System 1300 65, Cisco Telepresence System 3000, Cisco Telepresence System 3010, Cisco Telepresence System 3200.