Release date:
Updated on:
Affected Systems:
Cisco Telepresence Recording Server 1.7.2
Unaffected system:
Cisco Telepresence Recording Server 1.7.2.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 48932
Cve id: CVE-2011-2555
Cisco TelePresence is a Cisco TelePresence solution that collaborates with colleagues, partners, and customers around the world in a timely manner. Cisco TelePresence Recording Server converts Cisco TelePresence to a high-definition Recording studio.
The Cisco TelePresence Recording Server has the default root certificate verification Bypass Vulnerability. Remote attackers can exploit this vulnerability to obtain unauthorized management access to affected devices, resulting in full control of affected devices.
Cisco TelePresence Recording Server 1.7.2.0 contains the default root administrator account. Successful exploitation of this vulnerability allows remote attackers to use these default creden。 to modify system configurations and settings.
<* Source: Cisco
Link: http://www.cisco.com/warp/public/707/cisco-sa-20110729-tp.shtml
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cisco
-----
Cisco has released a Security Bulletin (cisco-sa-20110729-tp) and patches for this:
Cisco-sa-20110729-tp: Cisco TelePresence Recording Server Default Credentials for Root Account Vulnerability
Link: http://www.cisco.com/warp/public/707/cisco-sa-20110729-tp.shtml