CVE-2011-0354
The default configuration of Cisco Tandberg C Series Endpoints, and Tandberg E and EX Personal Video units, with software before TC4.0.0 has a blank password for the root account, which makes it easier for remote attackers to obtain access via an…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.0%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The default configuration of Cisco Tandberg C Series Endpoints, and Tandberg E and EX Personal Video units, with software before TC4.0.0 has a blank password for the root account, which makes it easier for remote attackers to obtain access via an unspecified login method.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 13.99% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- cisco/tandberg endpoint · cisco/tandberg personal video unit software · cisco/tandberg personal video unit
- Source
- psirt@cisco.com
References
- http://secunia.com/advisories/43158Vendor Advisory
- http://securityreason.com/securityalert/8060
- http://securitytracker.com/id?1025017
- http://tools.cisco.com/security/center/viewAlert.x?alertId=22314
- http://www.cisco.com/en/US/products/ps11422/products_security_advisory09186a0080b69541.shtmlVendor Advisory
- http://www.exploit-db.com/exploits/16100
- http://www.kb.cert.org/vuls/id/436854US Government Resource
- http://www.securityfocus.com/bid/46107
- http://secunia.com/advisories/43158Vendor Advisory
- http://securityreason.com/securityalert/8060
- http://securitytracker.com/id?1025017
- http://tools.cisco.com/security/center/viewAlert.x?alertId=22314
- http://www.cisco.com/en/US/products/ps11422/products_security_advisory09186a0080b69541.shtmlVendor Advisory
- http://www.exploit-db.com/exploits/16100
- http://www.kb.cert.org/vuls/id/436854US Government Resource
- http://www.securityfocus.com/bid/46107
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.