安全研究

安全漏洞
Cisco TelePresence Cisco Discovery Protocol远程代码执行漏洞

发布日期:2012-07-16
更新日期:2012-07-16

受影响系统:
Cisco TelePresence Multipoint Switch < 1.9.0
描述:
CVE ID: CVE-2012-2486

Cisco TelePresence是与在全球各地的同事、合作伙伴和客户及时展开协作的思科网真解决方案。

Cisco TelePresence Multipoint Switch、Cisco TelePresence Immersive Endpoint Devices、Cisco TelePresence Manager、Cisco TelePresence Recording Server上的Cisco Discovery Protocol组件可允许远程攻击者通过某些邻接关系并发送畸形CDP报文执行任意代码。

<*来源:Cisco
  
  链接:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-cts
        http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-ctsman
*>

建议:
厂商补丁:

Cisco
-----
Cisco已经为此发布了一个安全公告(cisco-sa-20120711-cts)以及相应补丁:

cisco-sa-20120711-cts:Multiple Vulnerabilities in Cisco TelePresence Immersive Endpoint Devices

链接:http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120711-cts

浏览次数:1764
严重程度:0(网友投票)
本安全漏洞由绿盟科技翻译整理,版权所有,未经许可,不得转载
绿盟科技给您安全的保障