Vulnerabilities > Cisco > Telepresence System Software > 1.6.0.3954

DATE CVE VULNERABILITY TITLE RISK
2012-07-12 CVE-2012-3075 OS Command Injection vulnerability in Cisco products
The administrative web interface on Cisco TelePresence Immersive Endpoint Devices before 1.7.4 allows remote authenticated users to execute arbitrary commands via a malformed request on TCP port 443, aka Bug ID CSCtn99724.
network
low complexity
cisco CWE-78
critical
9.0
2012-07-12 CVE-2012-3074 OS Command Injection vulnerability in Cisco products
An unspecified API on Cisco TelePresence Immersive Endpoint Devices before 1.9.1 allows remote attackers to execute arbitrary commands by leveraging certain adjacency and sending a malformed request on TCP port 61460, aka Bug ID CSCtz38382.
low complexity
cisco CWE-78
8.3
2012-07-12 CVE-2012-3073 Unspecified vulnerability in Cisco products
The IP implementation on Cisco TelePresence Multipoint Switch before 1.8.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server 1.8 and earlier allows remote attackers to cause a denial of service (networking outage or process crash) via (1) malformed IP packets, (2) a high rate of TCP connection requests, or (3) a high rate of TCP connection terminations, aka Bug IDs CSCti21830, CSCti21851, CSCtj19100, CSCtj19086, CSCtj19078, CSCty11219, CSCty11299, CSCty11323, and CSCty11338.
network
low complexity
cisco
7.8
2012-07-12 CVE-2012-2486 Code Injection vulnerability in Cisco products
The Cisco Discovery Protocol (CDP) implementation on Cisco TelePresence Multipoint Switch before 1.9.0, Cisco TelePresence Immersive Endpoint Devices before 1.9.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server before 1.8.1 allows remote attackers to execute arbitrary code by leveraging certain adjacency and sending a malformed CDP packet, aka Bug IDs CSCtz40953, CSCtz40947, CSCtz40965, and CSCtz40953.
low complexity
cisco CWE-94
8.3
2012-03-01 CVE-2012-0331 Resource Management Errors vulnerability in Cisco products
Cisco TelePresence Video Communication Server with software before X7.0.1 allows remote attackers to cause a denial of service (device crash) via a crafted SIP packet, as demonstrated by a SIP INVITE message from a Tandberg device, aka Bug ID CSCtq73319.
network
low complexity
cisco CWE-399
7.5
2012-03-01 CVE-2012-0330 Resource Management Errors vulnerability in Cisco products
Cisco TelePresence Video Communication Server with software before X7.0.1 allows remote attackers to cause a denial of service (device crash) via a malformed SIP message, aka Bug ID CSCtr20426.
network
low complexity
cisco CWE-399
7.8