CVE Vulnerabilities

CVE-2015-0611

Published: Feb 12, 2015 | Modified: Sep 08, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The administrative web-management portal in Cisco IX 8 (.0.1) and earlier on Cisco TelePresence IX5000 devices does not properly restrict the device-recovery accounts access, which allows remote authenticated users to obtain HelpDesk-equivalent privileges by leveraging device-recovery authentication, aka Bug ID CSCus74174.

Affected Software

Name Vendor Start Version End Version
Telepresence_system_software_ix Cisco 8.0.0 (including) 8.0.0 (including)
Telepresence_system_software_ix Cisco 8.0.1 (including) 8.0.1 (including)

References