cbcvebase.
CVE-2012-2486
published 2012-07-12

CVE-2012-2486: The Cisco Discovery Protocol (CDP) implementation on Cisco TelePresence Multipoint Switch before 1.9.0, Cisco TelePresence Immersive Endpoint Devices before…

PriorityP350high8.3CVSS 2.0
AVAACLAuNCCICAC
EPSS
1.75%
75.1th percentile
The Cisco Discovery Protocol (CDP) implementation on Cisco TelePresence Multipoint Switch before 1.9.0, Cisco TelePresence Immersive Endpoint Devices before 1.9.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server before 1.8.1 allows remote attackers to execute arbitrary code by leveraging certain adjacency and sending a malformed CDP packet, aka Bug IDs CSCtz40953, CSCtz40947, CSCtz40965, and CSCtz40953.

Affected

103 ranges· showing 25
VendorProductVersion rangeFixed in
ciscotelepresence_manager<= 1.8.1\(682\)
ciscotelepresence_manager
ciscotelepresence_manager
ciscotelepresence_manager
ciscotelepresence_manager
ciscotelepresence_manager
ciscotelepresence_manager
ciscotelepresence_manager
ciscotelepresence_manager
ciscotelepresence_manager
ciscotelepresence_manager
ciscotelepresence_manager
ciscotelepresence_manager
ciscotelepresence_manager
ciscotelepresence_manager
ciscotelepresence_manager
ciscotelepresence_manager
ciscotelepresence_manager
ciscotelepresence_manager
ciscotelepresence_multipoint_switch
ciscotelepresence_multipoint_switch_software<= 1.8.3\(9\)
ciscotelepresence_multipoint_switch_software
ciscotelepresence_multipoint_switch_software
ciscotelepresence_multipoint_switch_software
ciscotelepresence_multipoint_switch_software

CVSS provenance

nvdv2.08.3HIGHAV:A/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco9.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.