CVE-2011-2544
Cross-site scripting (XSS) vulnerability in the web interface in Cisco TelePresence System MXP Series F9.1 and earlier allows remote authenticated users to inject arbitrary web script or HTML via a crafted Call ID, as demonstrated by resultant cross-site request forgery (CSRF) attacks that change passwords or cause a denial of service, aka Bug ID CSCtq46488.
Published:Sep 23, 2011
Last Modified:Apr 11, 2025
EPS:Sep 23, 2011
EPSS Score:0.03434
CVSS Score:3.5
Affected Products
Vendor
Product
Action
Vendor
Cisco
Product
Telepresence Mxp Software
Cisco
Telepresence Mxp Software
Vendor
Cisco
Product
Telepresence System 1000 Mxp
Cisco
Telepresence System 1000 Mxp
Vendor
Cisco
Product
Telepresence System 1700 Mxp
Cisco
Telepresence System 1700 Mxp
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
