PT-2011-3923 · Cisco · Cisco Telepresence System Integrator C Series
David Klein
·
Publicado
2011-09-23
·
Atualizado
2018-10-09
·
CVE-2011-2543
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Telepresence System Integrator C Series versions 4.x before 4.2.0
Description
The issue is related to a buffer overflow in the cuil component, allowing remote authenticated users to cause a denial of service, such as endpoint reboot or process crash, or possibly execute arbitrary code. This can be achieved by sending a long location parameter to the
getxml program.Recommendations
For versions 4.x before 4.2.0, update to version 4.2.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the
getxml program to minimize the risk of exploitation.Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Telepresence System Integrator C Series