Severity
7.8HIGH
EPSS
0.6%
top 30.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 25
Latest updateMay 17

Description

Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x allow remote attackers to cause a denial of service (service crash) via a malformed SOAP request in conjunction with a spoofed TelePresence Manager that supplies an invalid IP address, aka Bug ID CSCth03605.

CVSS vector

AV:N/AC:L/C:N/I:N/A:CExploitability: 10.0 | Impact: 6.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-m22q-wr54-7hg4: Cisco TelePresence endpoint devices with software 12022-05-17
CVEList
CVE-2011-0377: Cisco TelePresence endpoint devices with software 12011-02-25

📋Vendor Advisories

1
Cisco
Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices2011-02-23
CVE-2011-0377 (HIGH CVSS 7.8) | Cisco TelePresence endpoint devices | cvebase.io