PT-2011-3923 · Cisco · Cisco Telepresence System Integrator C Series

David Klein

·

Published

2011-09-23

·

Updated

2018-10-09

·

CVE-2011-2543

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Telepresence System Integrator C Series versions 4.x before 4.2.0
Description The issue is related to a buffer overflow in the cuil component, allowing remote authenticated users to cause a denial of service, such as endpoint reboot or process crash, or possibly execute arbitrary code. This can be achieved by sending a long location parameter to the getxml program.
Recommendations For versions 4.x before 4.2.0, update to version 4.2.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the getxml program to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-2543

Affected Products

Cisco Telepresence System Integrator C Series