CVE-2012-3075
published 2012-07-12CVE-2012-3075: The administrative web interface on Cisco TelePresence Immersive Endpoint Devices before 1.7.4 allows remote authenticated users to execute arbitrary commands…
PriorityP352critical9CVSS 2.0
AVNACLAuSCCICAC
EPSS
2.17%
80.1th percentile
The administrative web interface on Cisco TelePresence Immersive Endpoint Devices before 1.7.4 allows remote authenticated users to execute arbitrary commands via a malformed request on TCP port 443, aka Bug ID CSCtn99724.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_immersive_endpoint_devices | — | — |
| cisco | telepresence_system_software | <= 1.7.2\(4937\) | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
CVSS provenance
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j923-487j-w32h: The administrative web interface on Cisco TelePresence Immersive Endpoint Devices before 1
ghsa_unreviewed·2022-05-17
CVE-2012-3075 [HIGH] CWE-78 GHSA-j923-487j-w32h: The administrative web interface on Cisco TelePresence Immersive Endpoint Devices before 1
The administrative web interface on Cisco TelePresence Immersive Endpoint Devices before 1.7.4 allows remote authenticated users to execute arbitrary commands via a malformed request on TCP port 443, aka Bug ID CSCtn99724.
Cisco
Multiple Vulnerabilities in Cisco TelePresence Immersive Endpoint Devices
vendor_cisco·2012-07-11·CVSS 9.0
CVE-2012-2486 [CRITICAL] Multiple Vulnerabilities in Cisco TelePresence Immersive Endpoint Devices
Multiple Vulnerabilities in Cisco TelePresence Immersive Endpoint Devices
Cisco TelePresence Endpoint devices contain the following vulnerabilities:
Cisco TelePresence API Remote Command Execution Vulnerability
Cisco TelePresence Remote Command Execution Vulnerability
Cisco TelePresence Cisco Discovery Protocol Remote Code Execution Vulnerability
Exploitation of the API Remote Command Execution vulnerability could allow an unauthenticated, adjacent attacker to inject commands into API requests. The injected commands will be executed by the underlying operating system in an elevated context.
Exploitation of the Remote Command Execution vulnerability could allow an authenticated, remote attacker to inject commands into requests made to the Administrative Web interface. The injected comma
Cisco
Multiple Vulnerabilities in Cisco TelePresence Immersive Endpoint Devices
vendor_cisco
CVE-2012-3075 Multiple Vulnerabilities in Cisco TelePresence Immersive Endpoint Devices
CVE-2012-3075: Multiple Vulnerabilities in Cisco TelePresence Immersive Endpoint Devices
Cisco TelePresence Endpoint devices contain the following vulnerabilities: Cisco TelePresence API Remote Command Execution Vulnerability Cisco TelePresence Remote Command Execution Vulnerability Cisco TelePresence Cisco Discovery Protocol Remote Code Execution Vulnerability Exploitation of the API Remote Command Execution vulnerability could allow an unauthenticated, adjacent attacker to inject commands into API requests. The injected commands will be executed by the underlying operating system in an elevated context. Exploitation of the Remote Command Execution vulnerability could allow an authenticated, remote attacker to inject commands into requests made to the Administrative Web interface. The inj
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2012-07-12
Published