CVE-2012-3074

high
Published 2012-07-12 · Modified 2026-04-29
CVSS v3
CVSS v2
8.3
VIR risk
8.3

Description

An unspecified API on Cisco TelePresence Immersive Endpoint Devices before 1.9.1 allows remote attackers to execute arbitrary commands by leveraging certain adjacency and sending a malformed request on TCP port 61460, aka Bug ID CSCtz38382.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@cisco.com — http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-cts

Application impact

VendorProductVersionsFixed
ciscotelepresence_system_software{"endIncluding":"1.9.0.1\\(3\\)"}
ciscotelepresence_system_software1.2.3\(1101\)
ciscotelepresence_system_software1.3.2\(1393\)
ciscotelepresence_system_software1.4.7\(2229\)
ciscotelepresence_system_software1.5.1\(2082\)
ciscotelepresence_system_software1.5.3\(2115\)
ciscotelepresence_system_software1.5.10\(3648\)
ciscotelepresence_system_software1.5.11\(3659\)
ciscotelepresence_system_software1.5.12\(3701\)
ciscotelepresence_system_software1.5.13\(3717\)
ciscotelepresence_system_software1.6.0\(3954\)
ciscotelepresence_system_software1.6.2\(4023\)
ciscotelepresence_system_software1.6.3\(4042\)
ciscotelepresence_system_software1.6.4\(4072\)
ciscotelepresence_system_software1.6.5\(4097\)
ciscotelepresence_system_software1.6.6\(4109\)
ciscotelepresence_system_software1.6.7\(4212\)
ciscotelepresence_system_software1.6.8\(4222\)
ciscotelepresence_system_software1.7.0.1\(4764\)
ciscotelepresence_system_software1.7.0.2\(4719\)
ciscotelepresence_system_software1.7.1\(4864\)
ciscotelepresence_system_software1.7.2\(4937\)
ciscotelepresence_system_software1.7.2.1\(2\)
ciscotelepresence_system_software1.7.4\(270\)
ciscotelepresence_system_software1.7.5\(42\)
ciscotelepresence_system_software1.7.6\(4\)
ciscotelepresence_system_software1.8.0\(55\)
ciscotelepresence_system_software1.8.1\(34\)
ciscotelepresence_system_software1.8.2\(11\)
ciscotelepresence_system_software1.8.3\(4\)
ciscotelepresence_system_software1.9.0\(46\)

References

CWEs

CWE-78

Verify integrity in audit chain (admin only). AS-IS.