CVE-2014-0661
published 2014-01-22CVE-2014-0661: The System Status Collection Daemon (SSCD) in Cisco TelePresence System 500-37, 1000, 1300-65, and 3xxx before 1.10.2(42), and 500-32, 1300-47, TX1310 65, and…
PriorityP344high8.3CVSS 2.0
AVAACLAuNCCICAC
EPSS
2.30%
81.3th percentile
The System Status Collection Daemon (SSCD) in Cisco TelePresence System 500-37, 1000, 1300-65, and 3xxx before 1.10.2(42), and 500-32, 1300-47, TX1310 65, and TX9xxx before 6.0.4(11), allows remote attackers to execute arbitrary commands or cause a denial of service (stack memory corruption) via a crafted XML-RPC message, aka Bug ID CSCui32796.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_system | — | — |
| cisco | telepresence_system_software | <= 1.10.1\(43\) | — |
| cisco | telepresence_system_software | <= 6.0.3\(33\) | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
| cisco | telepresence_system_software | — | — |
CVSS provenance
nvdv2.08.3HIGHAV:A/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco8.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco TelePresence System Software Command Execution Vulnerability
vendor_cisco·2014-01-22·CVSS 8.3
CVE-2014-0661 [HIGH] CWE-78 Cisco TelePresence System Software Command Execution Vulnerability
Cisco TelePresence System Software Command Execution Vulnerability
Cisco TelePresence System Software contains a vulnerability in the System Status Collection Daemon (SSCD) code that could allow an unauthenticated, adjacent attacker to execute arbitrary commands with the privileges of the root user.
Cisco has released software updates that address this vulnerability. No workarounds that mitigate this vulnerability are available.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140122-cts
Cisco
Cisco TelePresence System Software Command Execution Vulnerability
vendor_cisco
CVE-2014-0661 Cisco TelePresence System Software Command Execution Vulnerability
CVE-2014-0661: Cisco TelePresence System Software Command Execution Vulnerability
Cisco TelePresence System Software contains a vulnerability in the System Status Collection Daemon (SSCD) code that could allow an unauthenticated, adjacent attacker to execute arbitrary commands with the privileges of the root user. Cisco has released software updates that address this vulnerability. No
CWE: CWE-78, CWE-78
Bug IDs: CSCui32796, CSCui32796
GHSA
GHSA-7g4g-9h43-3xvc: The System Status Collection Daemon (SSCD) in Cisco TelePresence System 500-37, 1000, 1300-65, and 3xxx before 1
ghsa_unreviewed·2022-05-17
CVE-2014-0661 [HIGH] CWE-94 GHSA-7g4g-9h43-3xvc: The System Status Collection Daemon (SSCD) in Cisco TelePresence System 500-37, 1000, 1300-65, and 3xxx before 1
The System Status Collection Daemon (SSCD) in Cisco TelePresence System 500-37, 1000, 1300-65, and 3xxx before 1.10.2(42), and 500-32, 1300-47, TX1310 65, and TX9xxx before 6.0.4(11), allows remote attackers to execute arbitrary commands or cause a denial of service (stack memory corruption) via a crafted XML-RPC message, aka Bug ID CSCui32796.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/102362http://secunia.com/advisories/56533http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140122-ctshttp://www.securityfocus.com/bid/65071http://www.securitytracker.com/id/1029656https://exchange.xforce.ibmcloud.com/vulnerabilities/90624http://osvdb.org/102362http://secunia.com/advisories/56533http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140122-ctshttp://www.securityfocus.com/bid/65071http://www.securitytracker.com/id/1029656https://exchange.xforce.ibmcloud.com/vulnerabilities/90624
2014-01-22
Published