CVE-2012-3073
published 2012-07-12CVE-2012-3073: The IP implementation on Cisco TelePresence Multipoint Switch before 1.8.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server…
PriorityP337high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.80%
75.9th percentile
The IP implementation on Cisco TelePresence Multipoint Switch before 1.8.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server 1.8 and earlier allows remote attackers to cause a denial of service (networking outage or process crash) via (1) malformed IP packets, (2) a high rate of TCP connection requests, or (3) a high rate of TCP connection terminations, aka Bug IDs CSCti21830, CSCti21851, CSCtj19100, CSCtj19086, CSCtj19078, CSCty11219, CSCty11299, CSCty11323, and CSCty11338.
Affected
98 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_manager | <= 1.8.1\(682\) | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_manager | — | — |
| cisco | telepresence_multipoint_switch | — | — |
| cisco | telepresence_multipoint_switch_software | <= 1.8.0\(1026\) | — |
| cisco | telepresence_multipoint_switch_software | — | — |
| cisco | telepresence_multipoint_switch_software | — | — |
| cisco | telepresence_multipoint_switch_software | — | — |
| cisco | telepresence_multipoint_switch_software | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco TelePresence Recording Server
vendor_cisco·2012-07-11·CVSS 9.0
CVE-2012-2486 [CRITICAL] Multiple Vulnerabilities in Cisco TelePresence Recording Server
Multiple Vulnerabilities in Cisco TelePresence Recording Server
Cisco TelePresence Recording Server contains the following vulnerabilities:
Cisco TelePresence Malformed IP Packets Denial of Service Vulnerability
Cisco TelePresence Web Interface Command Injection
Cisco TelePresence Cisco Discovery Protocol Remote Code Execution Vulnerability
Exploitation of the Cisco TelePresence Malformed IP Packets Denial of Service Vulnerability may allow a remote, unauthenticated attacker to create a denial of service condition, preventing the product from responding to new connection requests and potentially causing some services and processes to crash.
Exploitation of the Cisco TelePresence Web Interface Command Injection may allow an authenticated, remote attacker to execute arbitrary commands o
Cisco
Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch
vendor_cisco·2012-07-11·CVSS 7.8
CVE-2012-2486 [HIGH] Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch
Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch
Cisco TelePresence Multipoint Switch contains the following vulnerabilities:
Cisco TelePresence Malformed IP Packets Denial of Service Vulnerability
Cisco TelePresence Cisco Discovery Protocol Remote Code Execution Vulnerability
Exploitation of the Cisco TelePresence Malformed IP Packets Denial of Service Vulnerability may allow an unauthenticated, remote attacker to create a denial of service (DoS) condition,
causing the product to become unresponsive to new connection requests and
potentially leading to termination services and processes.
Exploitation of the Cisco TelePresence Cisco Discovery Protocol Remote Code Execution Vulnerability may allow an unauthenticated, adjacent attacker to execute
arbitrary code with elev
Cisco
Multiple Vulnerabilities in Cisco TelePresence Manager
vendor_cisco·2012-07-11·CVSS 7.8
CVE-2012-2486 [HIGH] Multiple Vulnerabilities in Cisco TelePresence Manager
Multiple Vulnerabilities in Cisco TelePresence Manager
Cisco TelePresence Manager contains the following vulnerabilities:
Cisco TelePresence Malformed IP Packets Denial of Service Vulnerability
Cisco TelePresence Cisco Discovery Protocol Remote Code Execution Vulnerability
Exploitation of the Cisco TelePresence Malformed IP Packets Denial of Service Vulnerability may allow an unauthenticated, remote attacker to create a denial of service (DoS) condition,
causing the product to become unresponsive to new connection requests and
potentially leading to termination services and processes.
Exploitation of the Cisco TelePresence Cisco Discovery Protocol Remote Code Execution Vulnerability may allow an unauthenticated, adjacent attacker to execute
arbitrary code with elevated privileges.
Cis
Cisco
Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch
vendor_cisco
CVE-2012-3073 Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch
CVE-2012-3073: Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch
Cisco TelePresence Multipoint Switch contains the following vulnerabilities: Cisco TelePresence Malformed IP Packets Denial of Service Vulnerability Cisco TelePresence Cisco Discovery Protocol Remote Code Execution Vulnerability Exploitation of the Cisco TelePresence Malformed IP Packets Denial of Service Vulnerability may allow an unauthenticated, remote attacker to create a denial of service (DoS) condition, causing the product to become unresponsive to new connection requests and potentially leading to termination services and processes. Exploitation of the Cisco TelePresence Cisco Discovery Protocol Remote Code Execution Vulnerability may allow an unauthenticated, adjacent attacker to execute arbitrary code
GHSA
GHSA-98vh-jxvm-fp49: The IP implementation on Cisco TelePresence Multipoint Switch before 1
ghsa_unreviewed·2022-05-14
CVE-2012-3073 [HIGH] GHSA-98vh-jxvm-fp49: The IP implementation on Cisco TelePresence Multipoint Switch before 1
The IP implementation on Cisco TelePresence Multipoint Switch before 1.8.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server 1.8 and earlier allows remote attackers to cause a denial of service (networking outage or process crash) via (1) malformed IP packets, (2) a high rate of TCP connection requests, or (3) a high rate of TCP connection terminations, aka Bug IDs CSCti21830, CSCti21851, CSCtj19100, CSCtj19086, CSCtj19078, CSCty11219, CSCty11299, CSCty11323, and CSCty11338.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-ctmshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-ctrshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-ctsmanhttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-ctmshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-ctrshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-ctsman
2012-07-12
Published