Executive Summary

Summary
Title Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Informations
Name cisco-sa-20130619-tpc First vendor Publication 2013-06-19
Vendor Cisco Last vendor Modification 2013-06-19
Severity (Vendor) N/A Revision 1.0

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:A/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score 8.3 Attack Range Adjacent network
Cvss Impact Score 10 Attack Complexity Low
Cvss Expoit Score 6.5 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Cisco TelePresence TC and TE Software contain two vulnerabilities in the implementation of the Session Initiation Protocol (SIP) that could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition.

Additionally, Cisco TelePresence TC Software contain an adjacent root access vulnerability that could allow an attacker on the same physical or logical Layer-2 network as the affected system to gain an unauthenticated root shell.

Cisco has released free software updates that address these vulnerabilities. Workarounds that mitigate the Cisco TelePresence TC and TE Software SIP Denial of Service vulnerabilities are available. This advisory is available at the following link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20130619-tpc BEGIN PGP SIGNATURE Version: GnuPG/MacGPG2 v2.0.18 (Darwin)

iF4EAREKAAYFAlHBtlQACgkQUddfH3/BbTpOdwEAiBS9DSSPEUee26GiAHsj2UbF ts/iwI6PsKqrsZ8PWzsA/iY2dCpNgpMvtw7uCT6oUu6jj6DumUhebUKjh2TkotFO =4gGi END PGP SIGNATURE _______________________________________________ cust-security-announce mailing list cust-security-announce@cisco.com To unsubscribe, send the command "unsubscribe" in the subject of your message to cust-security-announce-leave@cisco.com

Original Source

Url : http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco (...)

CWE : Common Weakness Enumeration

% Id Name
33 % CWE-399 Resource Management Errors
33 % CWE-264 Permissions, Privileges, and Access Controls
33 % CWE-20 Improper Input Validation

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 42
Application 3
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Hardware 1
Os 4

Information Assurance Vulnerability Management (IAVM)

Date Description
2013-06-27 IAVM : 2013-A-0126 - Multiple Vulnerabilities in Cisco TelePresence Products
Severity : Category I - VMSKEY : V0039135

Nessus® Vulnerability Scanner

Date Description
2013-07-24 Name : The remote device is affected by a denial of service vulnerability.
File : cisco_telepresence_mcu_cve_2013_3377.nasl - Type : ACT_GATHER_INFO
2013-07-24 Name : The remote device is affected by a denial of service vulnerability.
File : cisco_telepresence_mcu_cve_2013_3378.nasl - Type : ACT_GATHER_INFO
2013-07-24 Name : The remote device is affected by a flaw that could allow an unauthorized user...
File : cisco_telepresence_mcu_cve_2013_3379.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
2
3
Date Informations
2014-02-17 10:22:10
  • Multiple Updates
2013-11-11 12:37:32
  • Multiple Updates
2013-06-21 21:21:51
  • Multiple Updates
2013-06-19 21:17:20
  • First insertion