Remote Code Execution in Cisco TelePresence System by Malicious XML-RPC Messages
CVE-2014-0661
Currently unrated
Key Information:
- Vendor
Cisco
- Status
- Vendor
- CVE Published:
- 22 January 2014
What is CVE-2014-0661?
The System Status Collection Daemon (SSCD) in various Cisco TelePresence Systems has a vulnerability that allows an attacker to execute arbitrary commands through specially crafted XML-RPC messages. This weakness can also lead to denial of service conditions due to stack memory corruption. Attackers exploiting this vulnerability may leverage it to gain unauthorized access to system functions, posing significant risks to network security.