CVE-2014-2172
published 2014-05-02CVE-2014-2172: Buffer overflow in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows local users to gain privileges by leveraging improper handling…
PriorityP423medium6.6CVSS 2.0
AVLACMAuSCCICAC
EPSS
0.34%
25.9th percentile
Buffer overflow in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows local users to gain privileges by leveraging improper handling of the u-boot compiler flag for internal executable files, aka Bug ID CSCub67693.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_tc_and_te | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_te_software | — | — |
| cisco | telepresence_te_software | — | — |
| cisco | telepresence_te_software | — | — |
CVSS provenance
nvdv2.06.6MEDIUMAV:L/AC:M/Au:S/C:C/I:C/A:C
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco TelePresence TC and TE Software u-boot Buffer Overflow Vulnerability
vendor_cisco·2014-04-30·CVSS 6.6
CVE-2014-2172 [MEDIUM] CWE-119 Cisco TelePresence TC and TE Software u-boot Buffer Overflow Vulnerability
Cisco TelePresence TC and TE Software u-boot Buffer Overflow Vulnerability
A vulnerability in the
implementation of executable utilities that use the universal bootloader
(u-boot) compiler of Cisco TelePresence TC and TE Software could allow
an authenticated, local attacker to create a buffer overflow and
possibly execute arbitrary code on the affected system.
The
vulnerability is due to the improper implementation of internal executable files
when the u-boot compiler flag is defined. An attacker could exploit
this vulnerability by accessing the affected system command-line interface (CLI) and try to run
the affected executable files.
Cisco has confirmed the vulnerability in a security advisory and released software updates.
A successful exploit would require local access to the target
Cisco
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
vendor_cisco·2014-04-30·CVSS 7.5
CVE-2014-2162 [HIGH] CWE-119 Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Cisco TelePresence TC and TE Software are affected by the following vulnerabilities:
Six Session Initiation Protocol (SIP) denial of service vulnerabilities
Cisco TelePresence TC and TE Software DNS Buffer Overflow Vulnerability
Cisco TelePresence TC and TE Software Input Validation Vulnerability
Cisco TelePresence TC and TE Software tshell Command Injection Vulnerability
Cisco TelePresence TC and TE Software Heap Overflow Vulnerability
Cisco TelePresence TC and TE Software U-Boot Buffer Overflow Vulnerability
Cisco TelePresence TC and TE Software Unauthenticated Serial Port Access Vulnerability
Cisco TelePresence TC H.225 Denial of Service Vulnerability
Successful exploitation of these vulnerabilities could allow an atta
Cisco
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
vendor_cisco
CVE-2014-2172 Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
CVE-2014-2172: Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Cisco TelePresence TC and TE Software are affected by the following vulnerabilities: Six Session Initiation Protocol (SIP) denial of service vulnerabilities Cisco TelePresence TC and TE Software DNS Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Input Validation Vulnerability Cisco TelePresence TC and TE Software tshell Command Injection Vulnerability Cisco TelePresence TC and TE Software Heap Overflow Vulnerability Cisco TelePresence TC and TE Software U-Boot Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Unauthenticated Serial Port Access Vulnerability Cisco TelePresence TC H.225 Denial of Service Vulnerability Successful exploitation of these vulnerabilities could a
GHSA
GHSA-r29v-vw6f-chmc: Buffer overflow in Cisco TelePresence TC Software 4
ghsa_unreviewed·2022-05-17
CVE-2014-2172 [MEDIUM] CWE-119 GHSA-r29v-vw6f-chmc: Buffer overflow in Cisco TelePresence TC Software 4
Buffer overflow in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows local users to gain privileges by leveraging improper handling of the u-boot compiler flag for internal executable files, aka Bug ID CSCub67693.
No detection rules found.
No public exploits indexed.
2014-05-02
Published