CVE-2013-3379
published 2013-06-21CVE-2013-3379: The firewall subsystem in Cisco TelePresence TC Software before 4.2 does not properly implement rules that grant access to hosts, which allows remote attackers…
PriorityP342high8.3CVSS 2.0
AVAACLAuNCCICAC
EPSS
1.00%
59.0th percentile
The firewall subsystem in Cisco TelePresence TC Software before 4.2 does not properly implement rules that grant access to hosts, which allows remote attackers to obtain shell access with root privileges by leveraging connectivity to the management network, aka Bug ID CSCts37781.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_tc_and_te | — | — |
| cisco | telepresence_tc_software | <= 4.1.2 | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
CVSS provenance
nvdv2.08.3HIGHAV:A/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco8.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
vendor_cisco·2013-06-19·CVSS 8.3
CVE-2013-3377 [HIGH] CWE-20 Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Cisco TelePresence TC and TE Software contain two vulnerabilities in the implementation of the Session Initiation Protocol (SIP) that could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition.
Additionally, Cisco TelePresence TC Software contain an adjacent root access vulnerability that could allow an attacker on the same physical or logical Layer-2 network as the affected system to gain an unauthenticated root shell.
Cisco has released software updates that address these vulnerabilities. Workarounds that mitigate the Cisco TelePresence TC and TE Software SIP Denial of Service vulnerabilities are available.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/
Cisco
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
vendor_cisco
CVE-2013-3379 Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
CVE-2013-3379: Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Cisco TelePresence TC and TE Software contain two vulnerabilities in the implementation of the Session Initiation Protocol (SIP) that could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition. Additionally, Cisco TelePresence TC Software contain an adjacent root access vulnerability that could allow an attacker on the same physical or logical Layer-2 network as the affected system to gain an unauthenticated root shell. Cisco has released software updates that address these vulnerabilities.
CWE: CWE-20, CWE-264, CWE-20, CWE-264
Bug IDs: CSCts37781, CSCue01743, CSCuf89557, CSCue01743, CSCuf89557
GHSA
GHSA-h3x8-v5rw-g7h2: The firewall subsystem in Cisco TelePresence TC Software before 4
ghsa_unreviewed·2022-05-17
CVE-2013-3379 [HIGH] GHSA-h3x8-v5rw-g7h2: The firewall subsystem in Cisco TelePresence TC Software before 4
The firewall subsystem in Cisco TelePresence TC Software before 4.2 does not properly implement rules that grant access to hosts, which allows remote attackers to obtain shell access with root privileges by leveraging connectivity to the management network, aka Bug ID CSCts37781.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-06-21
Published