CVE-2011-0388
Last modified
CVE-2011-0388 is a vulnerability of currently unknown severity. Cisco TelePresence Recording Server devices with software 1.6.x and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x do not properly restrict remote access to the Java servlet RMI interface, which allows remote attackers to cause a denial of service (memory consumption and web outage) via multiple crafted requests, aka Bug IDs CSCtg35830 and CSCtg35825.. EPSS estimates a 2.60% chance of exploitation in the next 30 days.
Description
Cisco TelePresence Recording Server devices with software 1.6.x and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x do not properly restrict remote access to the Java servlet RMI interface, which allows remote attackers to cause a denial of service (memory consumption and web outage) via multiple crafted requests, aka Bug IDs CSCtg35830 and CSCtg35825.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Telepresence Recording Server Software | 1.6.1 |
| Cisco | Telepresence Recording Server Software | 1.6.2 |
| Cisco | Telepresence Recording Server Software | 1.6.3 |
| Cisco | Telepresence Recording Server | All versions |
| Cisco | Telepresence Multipoint Switch Software | 1.0.4.0 |
| Cisco | Telepresence Multipoint Switch Software | 1.1.0 |
| Cisco | Telepresence Multipoint Switch Software | 1.1.1 |
| Cisco | Telepresence Multipoint Switch Software | 1.1.2 |
| Cisco | Telepresence Multipoint Switch Software | 1.5.0 |
| Cisco | Telepresence Multipoint Switch Software | 1.5.1 |
| Cisco | Telepresence Multipoint Switch Software | 1.5.2 |
| Cisco | Telepresence Multipoint Switch Software | 1.5.3 |
| Cisco | Telepresence Multipoint Switch Software | 1.5.4 |
| Cisco | Telepresence Multipoint Switch Software | 1.5.5 |
| Cisco | Telepresence Multipoint Switch Software | 1.5.6 |
| Cisco | Telepresence Multipoint Switch Software | 1.6.0 |
| Cisco | Telepresence Multipoint Switch Software | 1.6.1 |
| Cisco | Telepresence Multipoint Switch Software | 1.6.2 |
| Cisco | Telepresence Multipoint Switch Software | 1.6.3 |
| Cisco | Telepresence Multipoint Switch Software | 1.6.4 |
| Cisco | Telepresence Multipoint Switch | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-0388?
How severe is CVE-2011-0388?
How do I fix CVE-2011-0388?
Are you affected by CVE-2011-0388?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
