CVE-2012-3075

Description

The administrative web interface on Cisco TelePresence Immersive Endpoint Devices before 1.7.4 allows remote authenticated users to execute arbitrary commands via a malformed request on TCP port 443, aka Bug ID CSCtn99724.

Risk Information

Base Score
8.8
MODERATE
Vector
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.619

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities in Cisco TelePresence Immersive Endpoint Devices For Cisco TelePresence ManagerNCM
Multiple Vulnerabilities in Cisco TelePresence Immersive Endpoint Devices For Cisco TelePresence Administration SoftwareNCM
Multiple Vulnerabilities in Cisco TelePresence Immersive Endpoint Devices For Cisco TelePresence System 3000 SeriesNCM
Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) Vulnerability (CVE-2012-3075)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1705376Security Update for Cisco TelePresence Manager 1.9.0(186)
PATCH-1705874Security Update for Cisco TelePresence Administration Software 6.1.13_3
PATCH-1705615Security Update for Cisco TelePresence System 3000 Series 1.9.10:5

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234