imPC@ndo IT

Tracker / CVE-2013-3454

CVE-2013-3454

High 10.0

Cisco TelePresence System Software 1.10.1 and earlier on 500, 13X0, 1X00, 30X0, and 3X00 devices, and 6.0.3 and earlier on TX 9X00 devices, has a default password for the pwrecovery account, which makes it easier for remote attackers to modify the configuration or perform arbitrary actions via HTTPS requests, aka Bug ID CSCui43128.

Affected products and versions

cisco telepresence_system_1300
cisco telepresence_system_1300-65
cisco telepresence_system_3000
cisco telepresence_system_3010
cisco telepresence_system_3200
cisco telepresence_system_3210
cisco telepresence_system_500-32
cisco telepresence_system_500-37
cisco telepresence_system_software
cisco telepresence_system_software · … → 1.10.1
cisco telepresence_system_tx9000
cisco telepresence_system_tx9200

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References