CVE-2013-3454
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD
Description
Cisco TelePresence System Software 1.10.1 and earlier on 500, 13X0, 1X00, 30X0, and 3X00 devices, and 6.0.3 and earlier on TX 9X00 devices, has a default password for the pwrecovery account, which makes it easier for remote attackers to modify the configuration or perform arbitrary actions via HTTPS requests, aka Bug ID CSCui43128.
Affected (70)
Products: Cisco: Telepresence System Tx9000, Telepresence System Tx9200, Telepresence System Software, Telepresence System 1300, Telepresence System 1300 65, Telepresence System 3000, Telepresence System 3010, Telepresence System 3200, Telepresence System 3210, Telepresence System 500 32, Telepresence System 500 37
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| Version 6.0.0.1(4) |
| Running on/with | Platform Versions |
|---|---|
Cisco Telepresence System Software | Up to 6.0.3\(33\) |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.10.1 | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
Related CWEs
References (2)
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.