CVE-2011-0378
published 2011-02-25CVE-2011-0378: The XML-RPC implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a…
PriorityP347high8.3CVSS 2.0
AVAACLAuNCCICAC
EPSS
1.38%
68.9th percentile
The XML-RPC implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a TCP request, related to a "command injection vulnerability," aka Bug ID CSCtb52587.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_endpoint_devices | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
CVSS provenance
nvdv2.08.3HIGHAV:A/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices
vendor_cisco·2011-02-23·CVSS 10.0
CVE-2011-0372 [CRITICAL] CWE-119 Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices
Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices
Multiple vulnerabilities exist in the Cisco TelePresence solution; each
component of the solution is addressed independently in its own advisory. This
advisory addresses Cisco TelePresence endpoint devices and details the
following vulnerabilities:
Unauthenticated Common Gateway Interface (CGI) Access
CGI Command Injection
TFTP Information Disclosure
Malicious IP Address Injection
XML-Remote Procedure Call (RPC) Command Injection
Cisco Discovery Protocol Remote Code Execution
Duplicate Issue Identification in Other Cisco TelePresence Advisories
The Cisco Discovery Protocol Remote Code Execution vulnerability
affects Cisco TelePresence endpoint devices, Manager, Multipoint Switch, and
Recording Server. The defect that
Cisco
Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices
vendor_cisco
CVE-2011-0378 Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices
CVE-2011-0378: Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices
Multiple vulnerabilities exist in the Cisco TelePresence solution; each component of the solution is addressed independently in its own advisory. This advisory addresses Cisco TelePresence endpoint devices and
CWE: CWE-119, CWE-200, CWE-264, CWE-119, CWE-200, CWE-264, CWE-399, CWE-119, CWE-200, CWE-264, CWE-119, CWE-200, CWE-264, CWE-399
Bug IDs: CSCtd75754, CSCtd75761, CSCtd75766, CSCtd75769, CSCtb31640
GHSA
GHSA-hw6g-cw69-8qj2: The XML-RPC implementation on Cisco TelePresence endpoint devices with software 1
ghsa_unreviewed·2022-05-17
CVE-2011-0378 [HIGH] CWE-78 GHSA-hw6g-cw69-8qj2: The XML-RPC implementation on Cisco TelePresence endpoint devices with software 1
The XML-RPC implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a TCP request, related to a "command injection vulnerability," aka Bug ID CSCtb52587.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2011-02-25
Published