Vulnerability Intelligence Report
CVE-2014-0661
The System Status Collection Daemon (SSCD) in Cisco TelePresence System 500-37, 1000, 1300-65, and 3xxx before 1.10.2(42), and 500-32, 1300-47, TX1310 65, and TX9xxx before 6.0.4(11), allows remote attackers to execute arbitrary commands or cause a denial of service (stack memory corruption) via a crafted XML-RPC message, aka Bug ID CSCui32796.
No Active Exploit Signals
CVSS Base Score
8.3
HIGH
EPSS Probability:2.30%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| cisco | telepresence_system_software | 1.5.10\(3648\), 1.7.5\(42\), 1.7.6\(4\), 1.8.0\(55\), 1.8.1\(34\), 1.8.2\(11\), 1.8.3\(4\), 1.8.4\(13\), 1.8.5\(4\), 1.9.0\(46\), 1.9.1\(68\), 1.9.2\(19\), 1.9.3\(44\), 1.9.4\(19\), 1.9.5\(7\), 1.9.6\(2\), 1.9.6.1\(3\), 1.10.0, 1.10.0\(259\), 1.10.1, 6.0.0.1\(4\), 6.0.1\(50\), 6.0.2\(28\), 6.1.0\(90\) |
| cisco | telepresence_system_1000 | all |
| cisco | telepresence_system_1300-65 | all |
| cisco | telepresence_system_3000 | all |
| cisco | telepresence_system_3010 | all |
| cisco | telepresence_system_3200 | all |
| cisco | telepresence_system_3210 | all |
| cisco | telepresence_system_500-37 | all |
| cisco | telepresence_system_1100 | all |
| cisco | telepresence_system_500-32 | all |
| cisco | telepresence_system_tx1300_47 | all |
| cisco | telepresence_system_tx1310_65 | all |
| cisco | telepresence_system_tx9000 | all |
| cisco | telepresence_system_tx9200 | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
2.303%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Cisco Systems, Inc. · Hosted Service · USA |
| Reserved | 2014-01-02T00:00:00 |
| Published | 2014-01-22T21:00:00 |
| Patch Date | 2014-01-22 |
| Last Updated | 2024-08-06T09:20:19 |
Community Chatter & Buzz