CVE-2013-3454
Cisco TelePresence System Software 1.10.1 and earlier on 500, 13X0, 1X00, 30X0, and 3X00 devices, and 6.0.3 and earlier on TX 9X00 devices, has a default password for the pwrecovery account, which makes it easier for remote attackers to modify the…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.10%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cisco TelePresence System Software 1.10.1 and earlier on 500, 13X0, 1X00, 30X0, and 3X00 devices, and 6.0.3 and earlier on TX 9X00 devices, has a default password for the pwrecovery account, which makes it easier for remote attackers to modify the configuration or perform arbitrary actions via HTTPS requests, aka Bug ID CSCui43128.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 2.10% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- cisco/telepresence system tx9000 · cisco/telepresence system tx9200 · cisco/telepresence system software · cisco/telepresence system 1300 · cisco/telepresence system 1300-65 · cisco/telepresence system 3000 · cisco/telepresence system 3010 · cisco/telepresence system 3200 · cisco/telepresence system 3210 · cisco/telepresence system 500-32 · cisco/telepresence system 500-37
- Source
- psirt@cisco.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.