CVE-2011-0374
published 2011-02-25CVE-2011-0374: The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrary commands…
PriorityP349critical9CVSS 2.0
AVNACLAuSCCICAC
EPSS
2.79%
84.8th percentile
The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCtb31659.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_endpoint_devices | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
CVSS provenance
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices
vendor_cisco·2011-02-23·CVSS 10.0
CVE-2011-0372 [CRITICAL] CWE-119 Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices
Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices
Multiple vulnerabilities exist in the Cisco TelePresence solution; each
component of the solution is addressed independently in its own advisory. This
advisory addresses Cisco TelePresence endpoint devices and details the
following vulnerabilities:
Unauthenticated Common Gateway Interface (CGI) Access
CGI Command Injection
TFTP Information Disclosure
Malicious IP Address Injection
XML-Remote Procedure Call (RPC) Command Injection
Cisco Discovery Protocol Remote Code Execution
Duplicate Issue Identification in Other Cisco TelePresence Advisories
The Cisco Discovery Protocol Remote Code Execution vulnerability
affects Cisco TelePresence endpoint devices, Manager, Multipoint Switch, and
Recording Server. The defect that
Cisco
Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices
vendor_cisco
CVE-2011-0374 Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices
CVE-2011-0374: Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices
Multiple vulnerabilities exist in the Cisco TelePresence solution; each component of the solution is addressed independently in its own advisory. This advisory addresses Cisco TelePresence endpoint devices and
CWE: CWE-119, CWE-200, CWE-264, CWE-119, CWE-200, CWE-264, CWE-399, CWE-119, CWE-200, CWE-264, CWE-119, CWE-200, CWE-264, CWE-399
Bug IDs: CSCtd75754, CSCtd75761, CSCtd75766, CSCtd75769, CSCtb31640
GHSA
GHSA-45v6-m9r2-hc3m: The CGI implementation on Cisco TelePresence endpoint devices with software 1
ghsa_unreviewed·2022-05-17
CVE-2011-0374 [HIGH] CWE-78 GHSA-45v6-m9r2-hc3m: The CGI implementation on Cisco TelePresence endpoint devices with software 1
The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCtb31659.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2011-02-25
Published