CVE-2011-0380
published 2011-02-25CVE-2011-0380: Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to bypass authentication and invoke arbitrary methods via a malformed SOAP request, aka…
PriorityP350high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.38%
82.0th percentile
Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to bypass authentication and invoke arbitrary methods via a malformed SOAP request, aka Bug ID CSCtc59562.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8cpj-p4g2-v3pc: Cisco TelePresence Manager 1
ghsa_unreviewed·2022-05-17
CVE-2011-0380 [HIGH] CWE-287 GHSA-8cpj-p4g2-v3pc: Cisco TelePresence Manager 1
Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to bypass authentication and invoke arbitrary methods via a malformed SOAP request, aka Bug ID CSCtc59562.
Cisco
Multiple Vulnerabilities in Cisco TelePresence Manager
vendor_cisco·2011-02-23·CVSS 10.0
CVE-2011-0380 [CRITICAL] CWE-287 Multiple Vulnerabilities in Cisco TelePresence Manager
Multiple Vulnerabilities in Cisco TelePresence Manager
Multiple vulnerabilities exist in the Cisco TelePresence Manager. This
security advisory outlines the details of the following vulnerabilities:
Simple Object Access Protocol (SOAP) Authentication Bypass
Java Remote Method Invocation (RMI) Command Injection
Cisco Discovery Protocol Remote Code Execution
Duplicate Issue Identification in Other Cisco TelePresence Advisories
The Cisco Discovery Protocol remote code execution vulnerability
affects Cisco TelePresence endpoints, Manager, Multipoint Switch, and Recording
Server. The details about how the defect relates to each component are covered
in each associated advisory. The Cisco bug IDs for these defects are as
follows:
Cisco TelePresence endpoint devices - CSCtd75754
Cisco
Cisco
Multiple Vulnerabilities in Cisco TelePresence Manager
vendor_cisco
CVE-2011-0380 Multiple Vulnerabilities in Cisco TelePresence Manager
CVE-2011-0380: Multiple Vulnerabilities in Cisco TelePresence Manager
Multiple vulnerabilities exist in the Cisco TelePresence Manager. This security advisory outlines the
CWE: CWE-287, CWE-399, CWE-287, CWE-399
Bug IDs: CSCtd75754, CSCtd75761, CSCtd75766, CSCtd75769, CSCtc59562
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e14f.shtmlhttp://www.securityfocus.com/bid/46526http://www.securitytracker.com/id?1025111https://exchange.xforce.ibmcloud.com/vulnerabilities/65618http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e14f.shtmlhttp://www.securityfocus.com/bid/46526http://www.securitytracker.com/id?1025111https://exchange.xforce.ibmcloud.com/vulnerabilities/65618
2011-02-25
Published