Vulnerability Details CVE-2011-0378
The XML-RPC implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote attackers to execute arbitrary commands via a TCP request, related to a "command injection vulnerability," aka Bug ID CSCtb52587.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.019
EPSS Ranking 82.1%
CVSS Severity
CVSS v2 Score 8.3
Products affected by CVE-2011-0378
-
cpe:2.3:a:cisco:telepresence_system_software:1.2.3
-
cpe:2.3:a:cisco:telepresence_system_software:1.3.2
-
cpe:2.3:a:cisco:telepresence_system_software:1.4.7
-
cpe:2.3:a:cisco:telepresence_system_software:1.5.1
-
cpe:2.3:a:cisco:telepresence_system_software:1.5.10
-
cpe:2.3:a:cisco:telepresence_system_software:1.5.11
-
cpe:2.3:a:cisco:telepresence_system_software:1.5.12
-
cpe:2.3:a:cisco:telepresence_system_software:1.5.13
-
cpe:2.3:a:cisco:telepresence_system_software:1.5.3
-
cpe:2.3:h:cisco:telepresence_system_1000:-
-
cpe:2.3:h:cisco:telepresence_system_1100:-
-
cpe:2.3:h:cisco:telepresence_system_1300_series:*
-
cpe:2.3:h:cisco:telepresence_system_3000:-
-
cpe:2.3:h:cisco:telepresence_system_3200_series:*
-
cpe:2.3:h:cisco:telepresence_system_500_series:*