CVE-2012-2486
published 2012-07-12CVE-2012-2486: The Cisco Discovery Protocol (CDP) implementation on Cisco TelePresence Multipoint Switch before 1.9.0, Cisco TelePresence Immersive Endpoint Devices before…
PriorityP350high8.3CVSS 2.0
AVAACLAuNCCICAC
EPSS
1.75%
75.1th percentile
The Cisco Discovery Protocol (CDP) implementation on Cisco TelePresence Multipoint Switch before 1.9.0, Cisco TelePresence Immersive Endpoint Devices before 1.9.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server before 1.8.1 allows remote attackers to execute arbitrary code by leveraging certain adjacency and sending a malformed CDP packet, aka Bug IDs CSCtz40953, CSCtz40947, CSCtz40965, and CSCtz40953.
Affected
103 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_manager | <= 1.8.1\(682\) | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_multipoint_switch | — | — |
| cisco | telepresence_multipoint_switch_software | <= 1.8.3\(9\) | — |
| cisco | telepresence_multipoint_switch_software | — | — |
| cisco | telepresence_multipoint_switch_software | — | — |
| cisco | telepresence_multipoint_switch_software | — | — |
| cisco | telepresence_multipoint_switch_software | — | — |
CVSS provenance
nvdv2.08.3HIGHAV:A/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco TelePresence Recording Server
vendor_cisco·2012-07-11·CVSS 9.0
CVE-2012-2486 [CRITICAL] Multiple Vulnerabilities in Cisco TelePresence Recording Server
Multiple Vulnerabilities in Cisco TelePresence Recording Server
Cisco TelePresence Recording Server contains the following vulnerabilities:
Cisco TelePresence Malformed IP Packets Denial of Service Vulnerability
Cisco TelePresence Web Interface Command Injection
Cisco TelePresence Cisco Discovery Protocol Remote Code Execution Vulnerability
Exploitation of the Cisco TelePresence Malformed IP Packets Denial of Service Vulnerability may allow a remote, unauthenticated attacker to create a denial of service condition, preventing the product from responding to new connection requests and potentially causing some services and processes to crash.
Exploitation of the Cisco TelePresence Web Interface Command Injection may allow an authenticated, remote attacker to execute arbitrary commands o
Cisco
Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch
vendor_cisco·2012-07-11·CVSS 7.8
CVE-2012-2486 [HIGH] Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch
Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch
Cisco TelePresence Multipoint Switch contains the following vulnerabilities:
Cisco TelePresence Malformed IP Packets Denial of Service Vulnerability
Cisco TelePresence Cisco Discovery Protocol Remote Code Execution Vulnerability
Exploitation of the Cisco TelePresence Malformed IP Packets Denial of Service Vulnerability may allow an unauthenticated, remote attacker to create a denial of service (DoS) condition,
causing the product to become unresponsive to new connection requests and
potentially leading to termination services and processes.
Exploitation of the Cisco TelePresence Cisco Discovery Protocol Remote Code Execution Vulnerability may allow an unauthenticated, adjacent attacker to execute
arbitrary code with elev
Cisco
Multiple Vulnerabilities in Cisco TelePresence Manager
vendor_cisco·2012-07-11·CVSS 7.8
CVE-2012-2486 [HIGH] Multiple Vulnerabilities in Cisco TelePresence Manager
Multiple Vulnerabilities in Cisco TelePresence Manager
Cisco TelePresence Manager contains the following vulnerabilities:
Cisco TelePresence Malformed IP Packets Denial of Service Vulnerability
Cisco TelePresence Cisco Discovery Protocol Remote Code Execution Vulnerability
Exploitation of the Cisco TelePresence Malformed IP Packets Denial of Service Vulnerability may allow an unauthenticated, remote attacker to create a denial of service (DoS) condition,
causing the product to become unresponsive to new connection requests and
potentially leading to termination services and processes.
Exploitation of the Cisco TelePresence Cisco Discovery Protocol Remote Code Execution Vulnerability may allow an unauthenticated, adjacent attacker to execute
arbitrary code with elevated privileges.
Cis
Cisco
Multiple Vulnerabilities in Cisco TelePresence Immersive Endpoint Devices
vendor_cisco·2012-07-11·CVSS 9.0
CVE-2012-2486 [CRITICAL] Multiple Vulnerabilities in Cisco TelePresence Immersive Endpoint Devices
Multiple Vulnerabilities in Cisco TelePresence Immersive Endpoint Devices
Cisco TelePresence Endpoint devices contain the following vulnerabilities:
Cisco TelePresence API Remote Command Execution Vulnerability
Cisco TelePresence Remote Command Execution Vulnerability
Cisco TelePresence Cisco Discovery Protocol Remote Code Execution Vulnerability
Exploitation of the API Remote Command Execution vulnerability could allow an unauthenticated, adjacent attacker to inject commands into API requests. The injected commands will be executed by the underlying operating system in an elevated context.
Exploitation of the Remote Command Execution vulnerability could allow an authenticated, remote attacker to inject commands into requests made to the Administrative Web interface. The injected comma
Cisco
Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch
vendor_cisco
CVE-2012-2486 Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch
CVE-2012-2486: Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch
Cisco TelePresence Multipoint Switch contains the following vulnerabilities: Cisco TelePresence Malformed IP Packets Denial of Service Vulnerability Cisco TelePresence Cisco Discovery Protocol Remote Code Execution Vulnerability Exploitation of the Cisco TelePresence Malformed IP Packets Denial of Service Vulnerability may allow an unauthenticated, remote attacker to create a denial of service (DoS) condition, causing the product to become unresponsive to new connection requests and potentially leading to termination services and processes. Exploitation of the Cisco TelePresence Cisco Discovery Protocol Remote Code Execution Vulnerability may allow an unauthenticated, adjacent attacker to execute arbitrary code
GHSA
GHSA-p7jm-64r8-c5vp: The Cisco Discovery Protocol (CDP) implementation on Cisco TelePresence Multipoint Switch before 1
ghsa_unreviewed·2022-05-14
CVE-2012-2486 [HIGH] CWE-94 GHSA-p7jm-64r8-c5vp: The Cisco Discovery Protocol (CDP) implementation on Cisco TelePresence Multipoint Switch before 1
The Cisco Discovery Protocol (CDP) implementation on Cisco TelePresence Multipoint Switch before 1.9.0, Cisco TelePresence Immersive Endpoint Devices before 1.9.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server before 1.8.1 allows remote attackers to execute arbitrary code by leveraging certain adjacency and sending a malformed CDP packet, aka Bug IDs CSCtz40953, CSCtz40947, CSCtz40965, and CSCtz40953.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-ctmshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-ctrshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-ctshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-ctsmanhttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-ctmshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-ctrshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-ctshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-ctsman
2012-07-12
Published