SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2011-0379

Buffer overflow on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 1.6.x; Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x; Cisco TelePresence endpoint devices with software…

HIGH 7.9EPSS 2.15%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.15%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Buffer overflow on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 1.6.x; Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x; Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x; and Cisco TelePresence Manager 1.2.x, 1.3.x, 1.4.x, 1.5.x, and 1.6.2 allows remote attackers to execute arbitrary code via a crafted Cisco Discovery Protocol packet, aka Bug IDs CSCtd75769, CSCtd75766, CSCtd75754, and CSCtd75761.

CVSS 2.0
7.9 HIGHAV:A/AC:M/Au:N/C:C/I:C/A:C
EPSS
2.15% probability · 81th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
cisco/adaptive security appliance software · cisco/5500 series adaptive security appliance · cisco/asa 5500 · cisco/telepresence multipoint switch software · cisco/telepresence multipoint switch · cisco/telepresence system software · cisco/telepresence system 1000 · cisco/telepresence system 1100 · cisco/telepresence system 3000 · cisco/telepresence system 1300 series · cisco/telepresence system 3200 series · cisco/telepresence system 500 series · cisco/telepresence manager
Source
psirt@cisco.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.