CVE-2013-3454
Last modified
CVE-2013-3454 is a vulnerability of currently unknown severity. Cisco TelePresence System Software 1.10.1 and earlier on 500, 13X0, 1X00, 30X0, and 3X00 devices, and 6.0.3 and earlier on TX 9X00 devices, has a default password for the pwrecovery account, which makes it easier for remote attackers to modify the configuration or perform arbitrary actions via HTTPS requests, aka Bug ID CSCui43128.. EPSS estimates a 2.10% chance of exploitation in the next 30 days.
Description
Cisco TelePresence System Software 1.10.1 and earlier on 500, 13X0, 1X00, 30X0, and 3X00 devices, and 6.0.3 and earlier on TX 9X00 devices, has a default password for the pwrecovery account, which makes it easier for remote attackers to modify the configuration or perform arbitrary actions via HTTPS requests, aka Bug ID CSCui43128.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Telepresence System Tx9000 | All versions |
| Cisco | Telepresence System Tx9200 | All versions |
| Cisco | Telepresence System Software | 1.9.0\(46\) |
| Cisco | Telepresence System Software | 1.9.0.1\(3\) |
| Cisco | Telepresence System Software | 1.9.1\(68\) |
| Cisco | Telepresence System Software | 1.9.2 |
| Cisco | Telepresence System Software | 1.9.3 |
| Cisco | Telepresence System Software | 1.9.4 |
| Cisco | Telepresence System Software | 1.9.5 |
| Cisco | Telepresence System Software | 1.9.6 |
| Cisco | Telepresence System Software | 6.0.0.1\(4\) |
| Cisco | Telepresence System Software | 6.0.1\(50\) |
| Cisco | Telepresence System Software | 6.0.2\(28\) |
| Cisco | Telepresence System Software | <= 1.10.1 |
| Cisco | Telepresence System Software | 1.2.3 |
| Cisco | Telepresence System Software | 1.2.3\(1101\) |
| Cisco | Telepresence System Software | 1.3.2 |
| Cisco | Telepresence System Software | 1.3.2\(1393\) |
| Cisco | Telepresence System Software | 1.4.7 |
| Cisco | Telepresence System Software | 1.4.7\(2229\) |
| Cisco | Telepresence System Software | 1.5.1 |
| Cisco | Telepresence System Software | 1.5.1\(2082\) |
| Cisco | Telepresence System Software | 1.5.3 |
| Cisco | Telepresence System Software | 1.5.3\(2115\) |
| Cisco | Telepresence System Software | 1.5.10 |
| Cisco | Telepresence System Software | 1.5.10\(3648\) |
| Cisco | Telepresence System Software | 1.5.11 |
| Cisco | Telepresence System Software | 1.5.11\(3659\) |
| Cisco | Telepresence System Software | 1.5.12 |
| Cisco | Telepresence System Software | 1.5.12\(3701\) |
| Cisco | Telepresence System Software | 1.5.13 |
| Cisco | Telepresence System Software | 1.5.13\(3717\) |
| Cisco | Telepresence System Software | 1.6.0 |
| Cisco | Telepresence System Software | 1.6.0\(3954\) |
| Cisco | Telepresence System Software | 1.6.1 |
| Cisco | Telepresence System Software | 1.6.2 |
| Cisco | Telepresence System Software | 1.6.2\(4023\) |
| Cisco | Telepresence System Software | 1.6.3 |
| Cisco | Telepresence System Software | 1.6.3\(4042\) |
| Cisco | Telepresence System Software | 1.6.4 |
| Cisco | Telepresence System Software | 1.6.4\(4072\) |
| Cisco | Telepresence System Software | 1.6.5 |
| Cisco | Telepresence System Software | 1.6.5\(4097\) |
| Cisco | Telepresence System Software | 1.6.6 |
| Cisco | Telepresence System Software | 1.6.6\(4109\) |
| Cisco | Telepresence System Software | 1.6.7 |
| Cisco | Telepresence System Software | 1.6.7\(4212\) |
| Cisco | Telepresence System Software | 1.6.8 |
| Cisco | Telepresence System Software | 1.6.8\(4222\) |
| Cisco | Telepresence System Software | 1.7.0.1\(4764\) |
Showing 50 of 70 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-3454?
How severe is CVE-2013-3454?
How do I fix CVE-2013-3454?
Are you affected by CVE-2013-3454?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
