CVE-2013-3454
published 2013-08-08CVE-2013-3454: Cisco TelePresence System Software 1.10.1 and earlier on 500, 13X0, 1X00, 30X0, and 3X00 devices, and 6.0.3 and earlier on TX 9X00 devices, has a default…
PriorityP356critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.10%
79.5th percentile
Cisco TelePresence System Software 1.10.1 and earlier on 500, 13X0, 1X00, 30X0, and 3X00 devices, and 6.0.3 and earlier on TX 9X00 devices, has a default password for the pwrecovery account, which makes it easier for remote attackers to modify the configuration or perform arbitrary actions via HTTPS requests, aka Bug ID CSCui43128.
Affected
61 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_system_default_credentials | — | — |
| cisco | telepresence_system_software | <= 1.10.1 | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco TelePresence System Default Credentials Vulnerability
vendor_cisco·2013-08-07·CVSS 10.0
CVE-2013-3454 [CRITICAL] CWE-255 Cisco TelePresence System Default Credentials Vulnerability
Cisco TelePresence System Default Credentials Vulnerability
A vulnerability in Cisco TelePresence System could allow a remote attacker to access the web server via a user account that is created with default credentials.
The vulnerability is due to a default user account being created at installation time. An attacker could exploit this vulnerability by remotely accessing the web server and using the default account credentials. An exploit could allow the attacker to log in with the default credentials, which gives them full administrative rights to the system.
Workarounds that mitigate this vulnerability are available.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130807-tp
Cisco
Cisco TelePresence System Default Credentials Vulnerability
vendor_cisco
CVE-2013-3454 Cisco TelePresence System Default Credentials Vulnerability
CVE-2013-3454: Cisco TelePresence System Default Credentials Vulnerability
A vulnerability in Cisco TelePresence System could allow a remote attacker to access the web server via a user account that is created with default credentials. The vulnerability is due to a default user account being created at installation time. An attacker could exploit this vulnerability by remotely accessing the web server and using the default account credentials. An exploit could allow the attacker to log in with the default credentials, which gives them full administrative rights to the system.
CWE: CWE-255, CWE-255
Bug IDs: CSCui43128, CSCui43128
GHSA
GHSA-79wc-qq86-gqcv: Cisco TelePresence System Software 1
ghsa_unreviewed·2022-05-17
CVE-2013-3454 [HIGH] GHSA-79wc-qq86-gqcv: Cisco TelePresence System Software 1
Cisco TelePresence System Software 1.10.1 and earlier on 500, 13X0, 1X00, 30X0, and 3X00 devices, and 6.0.3 and earlier on TX 9X00 devices, has a default password for the pwrecovery account, which makes it easier for remote attackers to modify the configuration or perform arbitrary actions via HTTPS requests, aka Bug ID CSCui43128.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-08-08
Published