Vulnerability CVE-2012-2486


Published: 2012-07-12

Description:
The Cisco Discovery Protocol (CDP) implementation on Cisco TelePresence Multipoint Switch before 1.9.0, Cisco TelePresence Immersive Endpoint Devices before 1.9.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server before 1.8.1 allows remote attackers to execute arbitrary code by leveraging certain adjacency and sending a malformed CDP packet, aka Bug IDs CSCtz40953, CSCtz40947, CSCtz40965, and CSCtz40953.

Type:

CWE-94

(Improper Control of Generation of Code ('Code Injection'))

CVSS2 => (AV:A/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
8.3/10
10/10
6.5/10
Exploit range
Attack complexity
Authentication
Adjacent network
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Cisco -> Telepresence multipoint switch software 
Cisco -> Telepresence multipoint switch 
Cisco -> Telepresence manager 
Cisco -> Telepresence recording server 
Cisco -> Telepresence system software 
Cisco -> Telepresence system 1300 65 
Cisco -> Telepresence system 3000 
Cisco -> Telepresence system 3010 
Cisco -> Telepresence system 3200 
Cisco -> Telepresence system 3210 
Cisco -> Telepresence system t3 
Cisco -> Telepresence system tx1300 47 
Cisco -> Telepresence system tx1310 65 
Cisco -> Telepresence system tx9000 
Cisco -> Telepresence system tx9200 

 References:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-ctms
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-ctrs
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-cts
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-ctsman

Copyright 2024, cxsecurity.com

 

Back to Top