Cisco TelePresence Endpoint HTML Injection and Memory Corruption Vulnerabilities
BID:49670
Info
Cisco TelePresence Endpoint HTML Injection and Memory Corruption Vulnerabilities
| Bugtraq ID: | 49670 |
| Class: | Unknown |
| CVE: |
CVE-2011-2543 CVE-2011-2544 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 19 2011 12:00AM |
| Updated: | Sep 19 2011 12:00AM |
| Credit: | David Klein of Sense of Security Labs |
| Vulnerable: |
Cisco TelePresence Endpoint MXP F9.1 Cisco TelePresence Endpoint C TC4.1.2 |
| Not Vulnerable: | |
Discussion
Cisco TelePresence Endpoint HTML Injection and Memory Corruption Vulnerabilities
Cisco TelePresence Endpoint is prone to memory-corruption and HTML-injection vulnerabilities.
An attacker can exploit the HTML-injection issue to execute arbitrary script code in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials. Other attacks are also possible.
An attacker can exploit the memory-corruption issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
Cisco TelePresence Endpoint is prone to memory-corruption and HTML-injection vulnerabilities.
An attacker can exploit the HTML-injection issue to execute arbitrary script code in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials. Other attacks are also possible.
An attacker can exploit the memory-corruption issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
Exploit / POC
Cisco TelePresence Endpoint HTML Injection and Memory Corruption Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Cisco TelePresence Endpoint HTML Injection and Memory Corruption Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Cisco TelePresence Endpoint HTML Injection and Memory Corruption Vulnerabilities
References:
References:
- Cisco TelePresence Multiple Vulnerabilities (Sense Of Security)
- Product Homepage (Cisco)