[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195521

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-0661Date: (C)2014-01-23   (M)2023-12-22


The System Status Collection Daemon (SSCD) in Cisco TelePresence System 500-37, 1000, 1300-65, and 3xxx before 1.10.2(42), and 500-32, 1300-47, TX1310 65, and TX9xxx before 6.0.4(11), allows remote attackers to execute arbitrary commands or cause a denial of service (stack memory corruption) via a crafted XML-RPC message, aka Bug ID CSCui32796.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 8.3
Exploit Score: 6.5
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: ADJACENT_NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
OSVDB-102362
SECTRACK-1029656
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140122-cts
SECUNIA-56533
BID-65071
cisco-telepresence-cve20140661-command-exec(90624)

CPE    15
cpe:/h:cisco:telepresence_system_500-32:-
cpe:/h:cisco:telepresence_system_500-37:-
cpe:/h:cisco:telepresence_system_3200
cpe:/h:cisco:telepresence_system_tx9200
...
CWE    1
CWE-94

© SecPod Technologies