Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-0661


The System Status Collection Daemon (SSCD) in Cisco TelePresence System 500-37, 1000, 1300-65, and 3xxx before 1.10.2(42), and 500-32, 1300-47, TX1310 65, and TX9xxx before 6.0.4(11), allows remote attackers to execute arbitrary commands or cause a denial of service (stack memory corruption) via a crafted XML-RPC message, aka Bug ID CSCui32796.


Published

2014-01-22T21:55:03.560

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 8.3 (HIGH)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

6.5

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco telepresence_system_software ≤ 1.10.1\(43\) Yes
Application cisco telepresence_system_software 1.5.10\(3648\) Yes
Application cisco telepresence_system_software 1.7.5\(42\) Yes
Application cisco telepresence_system_software 1.7.6\(4\) Yes
Application cisco telepresence_system_software 1.8.0\(55\) Yes
Application cisco telepresence_system_software 1.8.1\(34\) Yes
Application cisco telepresence_system_software 1.8.2\(11\) Yes
Application cisco telepresence_system_software 1.8.3\(4\) Yes
Application cisco telepresence_system_software 1.8.4\(13\) Yes
Application cisco telepresence_system_software 1.8.5\(4\) Yes
Application cisco telepresence_system_software 1.9.0\(46\) Yes
Application cisco telepresence_system_software 1.9.1\(68\) Yes
Application cisco telepresence_system_software 1.9.2\(19\) Yes
Application cisco telepresence_system_software 1.9.3\(44\) Yes
Application cisco telepresence_system_software 1.9.4\(19\) Yes
Application cisco telepresence_system_software 1.9.5\(7\) Yes
Application cisco telepresence_system_software 1.9.6\(2\) Yes
Application cisco telepresence_system_software 1.9.6.1\(3\) Yes
Application cisco telepresence_system_software 1.10.0 Yes
Application cisco telepresence_system_software 1.10.0\(259\) Yes
Application cisco telepresence_system_software 1.10.1 Yes
Hardware cisco telepresence_system_1000 - Yes
Hardware cisco telepresence_system_1300-65 - Yes
Hardware cisco telepresence_system_3000 * Yes
Hardware cisco telepresence_system_3010 * Yes
Hardware cisco telepresence_system_3200 * Yes
Hardware cisco telepresence_system_3210 * Yes
Hardware cisco telepresence_system_500-37 - Yes
Application cisco telepresence_system_software ≤ 6.0.3\(33\) Yes
Application cisco telepresence_system_software 6.0.0.1\(4\) Yes
Application cisco telepresence_system_software 6.0.1\(50\) Yes
Application cisco telepresence_system_software 6.0.2\(28\) Yes
Application cisco telepresence_system_software 6.1.0\(90\) Yes
Hardware cisco telepresence_system_1100 - Yes
Hardware cisco telepresence_system_500-32 - Yes
Hardware cisco telepresence_system_tx1300_47 * Yes
Hardware cisco telepresence_system_tx1310_65 * Yes
Hardware cisco telepresence_system_tx9000 * Yes
Hardware cisco telepresence_system_tx9200 * Yes

References