CVE-2014-0661
The System Status Collection Daemon (SSCD) in Cisco TelePresence System 500-37, 1000, 1300-65, and 3xxx before 1.10.2(42), and 500-32, 1300-47, TX1310 65, and TX9xxx before 6.0.4(11), allows remote attackers to execute arbitrary commands or cause a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.30%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The System Status Collection Daemon (SSCD) in Cisco TelePresence System 500-37, 1000, 1300-65, and 3xxx before 1.10.2(42), and 500-32, 1300-47, TX1310 65, and TX9xxx before 6.0.4(11), allows remote attackers to execute arbitrary commands or cause a denial of service (stack memory corruption) via a crafted XML-RPC message, aka Bug ID CSCui32796.
- CVSS 2.0
- 8.3 HIGHAV:A/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 2.30% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- cisco/telepresence system software · cisco/telepresence system 1000 · cisco/telepresence system 1300-65 · cisco/telepresence system 3000 · cisco/telepresence system 3010 · cisco/telepresence system 3200 · cisco/telepresence system 3210 · cisco/telepresence system 500-37 · cisco/telepresence system 1100 · cisco/telepresence system 500-32 · cisco/telepresence system tx1300 47 · cisco/telepresence system tx1310 65 · cisco/telepresence system tx9000 · cisco/telepresence system tx9200
- Source
- psirt@cisco.com
References
- http://osvdb.org/102362
- http://secunia.com/advisories/56533
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140122-ctsVendor Advisory
- http://www.securityfocus.com/bid/65071Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029656Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90624
- http://osvdb.org/102362
- http://secunia.com/advisories/56533
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140122-ctsVendor Advisory
- http://www.securityfocus.com/bid/65071Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029656Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90624
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.