Vulnerability Name:

CVE-2011-0377 (CCN-65616)

Assigned:2011-02-23
Published:2011-02-23
Updated:2017-08-17
Summary:Cisco TelePresence endpoint devices with software 1.2.x through 1.6.x allow remote attackers to cause a denial of service (service crash) via a malformed SOAP request in conjunction with a spoofed TelePresence Manager that supplies an invalid IP address, aka Bug ID CSCth03605.
CVSS v3 Severity:7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
5.8 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-399
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2011-0377

Source: CCN
Type: SA43488
Cisco ASA 5500 Series Multiple Vulnerabilities

Source: CCN
Type: cisco-sa-20110223-telepresence-cts
Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices

Source: CISCO
Type: Vendor Advisory
20110223 Multiple Vulnerabilities in Cisco TelePresence Endpoint Devices

Source: CCN
Type: OSVDB ID: 72592
Cisco TelePresence Spoofed SOAP / Manager Request Remote DoS

Source: CCN
Type: BID-46517
Cisco TelePresence Endpoint Devices Multiple Vulnerabilities

Source: SECTRACK
Type: UNKNOWN
1025112

Source: XF
Type: UNKNOWN
cisco-endpoint-ipaddress-dos(65616)

Source: XF
Type: UNKNOWN
cisco-endpoint-ipaddress-dos(65616)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:cisco:telepresence_system_software:1.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.3.2:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.4.7:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.3:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.10:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.11:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.12:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.13:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.0:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.2:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.3:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.4:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.5:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.6:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.7:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.8:*:*:*:*:*:*:*
  • AND
  • cpe:/h:cisco:telepresence_system_1000:*:*:*:*:*:*:*:*
  • OR cpe:/h:cisco:telepresence_system_1100:*:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:cisco:telepresence_system_software:1.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.3.2:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.4.7:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.3:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.10:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.11:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.12:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.13:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.0:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.2:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.3:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.4:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.5:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.6:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.7:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.8:*:*:*:*:*:*:*
  • AND
  • cpe:/h:cisco:telepresence_system_3000:*:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/a:cisco:telepresence_system_software:1.5.10:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.11:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.12:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.13:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.0:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.2:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.3:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.4:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.5:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.6:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.7:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.8:*:*:*:*:*:*:*
  • AND
  • cpe:/h:cisco:telepresence_system_1300_series:*:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/a:cisco:telepresence_system_software:1.4.7:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.3:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.10:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.11:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.12:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.13:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.0:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.2:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.3:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.4:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.5:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.6:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.7:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.8:*:*:*:*:*:*:*
  • AND
  • cpe:/h:cisco:telepresence_system_3200_series:*:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/a:cisco:telepresence_system_software:1.4.7:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.3:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.10:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.11:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.12:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.5.13:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.0:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.2:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.3:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.4:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.5:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.6:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.7:*:*:*:*:*:*:*
  • OR cpe:/a:cisco:telepresence_system_software:1.6.8:*:*:*:*:*:*:*
  • AND
  • cpe:/h:cisco:telepresence_system_500_series:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    cisco telepresence system software 1.2.3
    cisco telepresence system software 1.3.2
    cisco telepresence system software 1.4.7
    cisco telepresence system software 1.5.1
    cisco telepresence system software 1.5.3
    cisco telepresence system software 1.5.10
    cisco telepresence system software 1.5.11
    cisco telepresence system software 1.5.12
    cisco telepresence system software 1.5.13
    cisco telepresence system software 1.6.0
    cisco telepresence system software 1.6.2
    cisco telepresence system software 1.6.3
    cisco telepresence system software 1.6.4
    cisco telepresence system software 1.6.5
    cisco telepresence system software 1.6.6
    cisco telepresence system software 1.6.7
    cisco telepresence system software 1.6.8
    cisco telepresence system 1000 *
    cisco telepresence system 1100 *
    cisco telepresence system software 1.2.3
    cisco telepresence system software 1.3.2
    cisco telepresence system software 1.4.7
    cisco telepresence system software 1.5.1
    cisco telepresence system software 1.5.3
    cisco telepresence system software 1.5.10
    cisco telepresence system software 1.5.11
    cisco telepresence system software 1.5.12
    cisco telepresence system software 1.5.13
    cisco telepresence system software 1.6.0
    cisco telepresence system software 1.6.2
    cisco telepresence system software 1.6.3
    cisco telepresence system software 1.6.4
    cisco telepresence system software 1.6.5
    cisco telepresence system software 1.6.6
    cisco telepresence system software 1.6.7
    cisco telepresence system software 1.6.8
    cisco telepresence system 3000 *
    cisco telepresence system software 1.5.10
    cisco telepresence system software 1.5.11
    cisco telepresence system software 1.5.12
    cisco telepresence system software 1.5.13
    cisco telepresence system software 1.6.0
    cisco telepresence system software 1.6.2
    cisco telepresence system software 1.6.3
    cisco telepresence system software 1.6.4
    cisco telepresence system software 1.6.5
    cisco telepresence system software 1.6.6
    cisco telepresence system software 1.6.7
    cisco telepresence system software 1.6.8
    cisco telepresence system 1300 series *
    cisco telepresence system software 1.4.7
    cisco telepresence system software 1.5.1
    cisco telepresence system software 1.5.3
    cisco telepresence system software 1.5.10
    cisco telepresence system software 1.5.11
    cisco telepresence system software 1.5.12
    cisco telepresence system software 1.5.13
    cisco telepresence system software 1.6.0
    cisco telepresence system software 1.6.2
    cisco telepresence system software 1.6.3
    cisco telepresence system software 1.6.4
    cisco telepresence system software 1.6.5
    cisco telepresence system software 1.6.6
    cisco telepresence system software 1.6.7
    cisco telepresence system software 1.6.8
    cisco telepresence system 3200 series *
    cisco telepresence system software 1.4.7
    cisco telepresence system software 1.5.1
    cisco telepresence system software 1.5.3
    cisco telepresence system software 1.5.10
    cisco telepresence system software 1.5.11
    cisco telepresence system software 1.5.12
    cisco telepresence system software 1.5.13
    cisco telepresence system software 1.6.0
    cisco telepresence system software 1.6.2
    cisco telepresence system software 1.6.3
    cisco telepresence system software 1.6.4
    cisco telepresence system software 1.6.5
    cisco telepresence system software 1.6.6
    cisco telepresence system software 1.6.7
    cisco telepresence system software 1.6.8
    cisco telepresence system 500 series *