Skip to main content

Cisco TelePresence System Default Credentials Vulnerability

Last Update Date: 8 Aug 2013 10:02 Release Date: 8 Aug 2013 3292 Views

RISK: High Risk

TYPE: Clients - Im, Chat & Voip

TYPE: Im, Chat & Voip

A vulnerability has been identified in Cisco TelePresence. A remote user can gain full control of the target system.

 

The web server contains an administrative user account with default credentials. A remote user can access the system using these authentication credentials.

 

Note: Vendor patch is currently unavailable.


Impact

  • Remote Code Execution
  • Security Restriction Bypass

System / Technologies affected

  • Cisco TelePresence System Series 500, 13X0, 1X00, 3X00, and 30X0 devices running CiscoTelePresence System Software Releases 1.10.1 and prior
  • Cisco TelePresence TX 9X00 Series devices running Cisco TelePresence System Software Releases 6.0.3 and prior

Solutions


Vulnerability Identifier


Source


Related Link