imPC@ndo IT

Tracker / CVE-2012-2486

CVE-2012-2486

High 8.3

The Cisco Discovery Protocol (CDP) implementation on Cisco TelePresence Multipoint Switch before 1.9.0, Cisco TelePresence Immersive Endpoint Devices before 1.9.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server before 1.8.1 allows remote attackers to execute arbitrary code by leveraging certain adjacency and sending a malformed CDP packet, aka Bug IDs CSCtz40953, CSCtz40947, CSCtz40965, and CSCtz40953.

Affected products and versions

cisco telepresence_manager
cisco telepresence_manager · … → 1.8.1\(682\)
cisco telepresence_multipoint_switch
cisco telepresence_multipoint_switch_software
cisco telepresence_multipoint_switch_software · … → 1.8.3\(9\)
cisco telepresence_recording_server
cisco telepresence_recording_server · … → 1.8.0\(160\)
cisco telepresence_system_1300_65
cisco telepresence_system_3000
cisco telepresence_system_3010
cisco telepresence_system_3200
cisco telepresence_system_3210
cisco telepresence_system_software
cisco telepresence_system_software · … → 1.9.0.1\(3\)
cisco telepresence_system_t3
cisco telepresence_system_tx1300_47
cisco telepresence_system_tx1310_65
cisco telepresence_system_tx9000
cisco telepresence_system_tx9200

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References