CVE-2012-3074

Description

An unspecified API on Cisco TelePresence Immersive Endpoint Devices before 1.9.1 allows remote attackers to execute arbitrary commands by leveraging certain adjacency and sending a malformed request on TCP port 61460, aka Bug ID CSCtz38382.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.904

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities in Cisco TelePresence Immersive Endpoint Devices For Cisco TelePresence ManagerNCM
Multiple Vulnerabilities in Cisco TelePresence Immersive Endpoint Devices For Cisco TelePresence Administration SoftwareNCM
Multiple Vulnerabilities in Cisco TelePresence Immersive Endpoint Devices For Cisco TelePresence System 3000 SeriesNCM
Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) Vulnerability (CVE-2012-3074)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1705376Security Update for Cisco TelePresence Manager 1.9.0(186)
PATCH-1705874Security Update for Cisco TelePresence Administration Software 6.1.13_3
PATCH-1705615Security Update for Cisco TelePresence System 3000 Series 1.9.10:5

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234