Podatność CVE-2012-2486


Publikacja: 2012-07-12

Opis:
The Cisco Discovery Protocol (CDP) implementation on Cisco TelePresence Multipoint Switch before 1.9.0, Cisco TelePresence Immersive Endpoint Devices before 1.9.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server before 1.8.1 allows remote attackers to execute arbitrary code by leveraging certain adjacency and sending a malformed CDP packet, aka Bug IDs CSCtz40953, CSCtz40947, CSCtz40965, and CSCtz40953.

Typ:

CWE-94

(Improper Control of Generation of Code ('Code Injection'))

CVSS2 => (AV:A/AC:L/Au:N/C:C/I:C/A:C)

Ogólna skala CVSS
Znaczenie
Łatwość wykorzystania
8.3/10
10/10
6.5/10
Wymagany dostęp
Złożoność ataku
Autoryzacja
Sieć lokalna
Niska
Nie wymagana
Wpływ na poufność
Wpływ na integralność
Wpływ na dostępność
Pełny
Pełny
Pełny
Affected software
Cisco -> Telepresence multipoint switch software 
Cisco -> Telepresence multipoint switch 
Cisco -> Telepresence manager 
Cisco -> Telepresence recording server 
Cisco -> Telepresence system software 
Cisco -> Telepresence system 1300 65 
Cisco -> Telepresence system 3000 
Cisco -> Telepresence system 3010 
Cisco -> Telepresence system 3200 
Cisco -> Telepresence system 3210 
Cisco -> Telepresence system t3 
Cisco -> Telepresence system tx1300 47 
Cisco -> Telepresence system tx1310 65 
Cisco -> Telepresence system tx9000 
Cisco -> Telepresence system tx9200 

 Referencje:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-ctms
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-ctrs
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-cts
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-ctsman

Copyright 2024, cxsecurity.com

 

Back to Top