CVE-2011-0381
published 2011-02-25CVE-2011-0381: Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to perform unspecified actions and consequently execute arbitrary code via a crafted…
PriorityP358critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.46%
91.8th percentile
Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to perform unspecified actions and consequently execute arbitrary code via a crafted request to the Java RMI interface, related to a "command injection vulnerability," aka Bug ID CSCtf97085.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco TelePresence Manager
vendor_cisco·2011-02-23·CVSS 10.0
CVE-2011-0380 [CRITICAL] CWE-287 Multiple Vulnerabilities in Cisco TelePresence Manager
Multiple Vulnerabilities in Cisco TelePresence Manager
Multiple vulnerabilities exist in the Cisco TelePresence Manager. This
security advisory outlines the details of the following vulnerabilities:
Simple Object Access Protocol (SOAP) Authentication Bypass
Java Remote Method Invocation (RMI) Command Injection
Cisco Discovery Protocol Remote Code Execution
Duplicate Issue Identification in Other Cisco TelePresence Advisories
The Cisco Discovery Protocol remote code execution vulnerability
affects Cisco TelePresence endpoints, Manager, Multipoint Switch, and Recording
Server. The details about how the defect relates to each component are covered
in each associated advisory. The Cisco bug IDs for these defects are as
follows:
Cisco TelePresence endpoint devices - CSCtd75754
Cisco
Cisco
Multiple Vulnerabilities in Cisco TelePresence Manager
vendor_cisco
CVE-2011-0381 Multiple Vulnerabilities in Cisco TelePresence Manager
CVE-2011-0381: Multiple Vulnerabilities in Cisco TelePresence Manager
Multiple vulnerabilities exist in the Cisco TelePresence Manager. This security advisory outlines the
CWE: CWE-287, CWE-399, CWE-287, CWE-399
Bug IDs: CSCtd75754, CSCtd75761, CSCtd75766, CSCtd75769, CSCtc59562
GHSA
GHSA-5c56-7q2q-qv2j: Cisco TelePresence Manager 1
ghsa_unreviewed·2022-05-17
CVE-2011-0381 [HIGH] CWE-78 GHSA-5c56-7q2q-qv2j: Cisco TelePresence Manager 1
Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to perform unspecified actions and consequently execute arbitrary code via a crafted request to the Java RMI interface, related to a "command injection vulnerability," aka Bug ID CSCtf97085.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e14f.shtmlhttp://www.securityfocus.com/bid/46526http://www.securitytracker.com/id?1025111https://exchange.xforce.ibmcloud.com/vulnerabilities/65619http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e14f.shtmlhttp://www.securityfocus.com/bid/46526http://www.securitytracker.com/id?1025111https://exchange.xforce.ibmcloud.com/vulnerabilities/65619
2011-02-25
Published