Severity
6.6MEDIUM
EPSS
0.1%
top 75.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 2
Latest updateMay 17

Description

Buffer overflow in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows local users to gain privileges by leveraging improper handling of the u-boot compiler flag for internal executable files, aka Bug ID CSCub67693.

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 2.7 | Impact: 10.0

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-r29v-vw6f-chmc: Buffer overflow in Cisco TelePresence TC Software 42022-05-17
CVEList
CVE-2014-2172: Buffer overflow in Cisco TelePresence TC Software 42014-05-02

📋Vendor Advisories

2
Cisco
Cisco TelePresence TC and TE Software u-boot Buffer Overflow Vulnerability2014-04-30
Cisco
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software2014-04-30

💬Community

1
Bugzilla
CVE-2015-2172 dokuwiki: privilege escalation in RPC API2015-03-02