CERT-In Vulnerability Note
CIVN-2013-0208
Cisco TelePresence VX Clinical Assistant Administrative Password Reset Vulnerability
Original Issue Date:November 21, 2013
Severity Rating: HIGH
Systems Affected
- Cisco TelePresence VX Clinical Assistant devices Software version 1.2
Overview
A vulnerability have been reported in the WIL-A module of Cisco TelePresence VX Clinical Assistant which could allow an unauthenticated remote attacker to log in as the admin user of the device using a blank password.
Description
This vulnerability is due to a coding error that resets the password for the admin user to a blank password on every reboot. An unauthenticated remote attacker could exploit this vulnerability by logging in to the administrative interface as the admin user with a blank password.
Successful exploitation of this vulnerability could allow a remote attacker to gain unauthorized access to the targeted system.
Solution
Apply appropriate updates as mentioned in CISCO advisory
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20131106-tvxca
Vendor Information
CISCO
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20131106-tvxca
References
CISCO
http://tools.cisco.com/security/center/viewAlert.x?alertId=31571
Secunia
http://secunia.com/advisories/55613/
CVE Name
CVE-2013-5558
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|