SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-3454

Cisco TelePresence System Software 1.10.1 and earlier on 500, 13X0, 1X00, 30X0, and 3X00 devices, and 6.0.3 and earlier on TX 9X00 devices, has a default password for the pwrecovery account, which makes it easier for remote attackers to modify the…

HIGH 10.0EPSS 2.10%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.10%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Cisco TelePresence System Software 1.10.1 and earlier on 500, 13X0, 1X00, 30X0, and 3X00 devices, and 6.0.3 and earlier on TX 9X00 devices, has a default password for the pwrecovery account, which makes it easier for remote attackers to modify the configuration or perform arbitrary actions via HTTPS requests, aka Bug ID CSCui43128.

CVSS 2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
2.10% probability · 81th percentile
CISA KEV
Not listed
Weakness
CWE-255
Affected
cisco/telepresence system tx9000 · cisco/telepresence system tx9200 · cisco/telepresence system software · cisco/telepresence system 1300 · cisco/telepresence system 1300-65 · cisco/telepresence system 3000 · cisco/telepresence system 3010 · cisco/telepresence system 3200 · cisco/telepresence system 3210 · cisco/telepresence system 500-32 · cisco/telepresence system 500-37
Source
psirt@cisco.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.