CVE-2011-0383
Summary
| CVE | CVE-2011-0383 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-02-25 12:00:00 UTC |
| Updated | 2017-08-17 01:33:00 UTC |
| Description | The Java Servlet framework on Cisco TelePresence Recording Server devices with software 1.6.x before 1.6.2 and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x does not require administrative authentication for unspecified actions, which allows remote attackers to execute arbitrary code via a crafted request, aka Bug IDs CSCtf42005 and CSCtf42008. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Security Advisory: Multiple Vulnerabilities in Cisco TelePresence Recording Server - Cisco Systems | CISCO | www.cisco.com | Vendor Advisory |
| Cisco TelePresence Multipoint Switch and Recording Server Security Bypass Vulnerability | BID | www.securityfocus.com | |
| Cisco Security Advisory: Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch - Cisco Systems | CISCO | www.cisco.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Cisco TelePresence Recording Server Bugs Let Remote Users Deny Service and Take Full Control of the Target Device - SecurityTracker | SECTRACK | www.securitytracker.com | |
| Cisco TelePresence Multipoint Switch Flaws Let Remote Users Deny Service and Execute Arbitrary Code - SecurityTracker | SECTRACK | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.