CVE-2013-3454 - CVE House
Back to Database
Status published Critical CVE-2013-3454

Cisco TelePresence System Software 1.10.1 and earlier on 500, 13X0,...

Vulnerability Description

Cisco TelePresence System Software 1.10.1 and earlier on 500, 13X0, 1X00, 30X0, and 3X00 devices, and 6.0.3 and earlier on TX 9X00 devices, has a default password for the pwrecovery account, which makes it easier for remote attackers to modify the configuration or perform arbitrary actions via HTTPS requests, aka Bug ID CSCui43128.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-3454

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

telepresence system tx9000, telepresence system tx9200, telepresence system software, telepresence system 1300, telepresence system 1300-65, telepresence system 3000, telepresence system 3010, telepresence system 3200, telepresence system 3210, telepresence system 500-32, telepresence system 500-37
Vulnerable Versions:
1.9.0\(46\), 1.9.0.1\(3\), 1.9.1\(68\), 1.9.2, 1.9.3, 1.9.4, 1.9.5, 1.9.6, 6.0.0.1\(4\), 6.0.1\(50\), 6.0.2\(28\), 0, 1.2.3, 1.2.3\(1101\), 1.3.2, 1.3.2\(1393\), 1.4.7, 1.4.7\(2229\), 1.5.1, 1.5.1\(2082\), 1.5.3, 1.5.3\(2115\), 1.5.10, 1.5.10\(3648\), 1.5.11, 1.5.11\(3659\), 1.5.12, 1.5.12\(3701\), 1.5.13, 1.5.13\(3717\), 1.6.0, 1.6.0\(3954\), 1.6.1, 1.6.2, 1.6.2\(4023\), 1.6.3, 1.6.3\(4042\), 1.6.4, 1.6.4\(4072\), 1.6.5, 1.6.5\(4097\), 1.6.6, 1.6.6\(4109\), 1.6.7, 1.6.7\(4212\), 1.6.8, 1.6.8\(4222\), 1.7.0.1\(4764\), 1.7.0.2\(4719\), 1.7.1\(4864\), 1.7.2\(4937\), 1.7.2.1\(2\), 1.7.4\(270\), 1.7.5\(42\), 1.7.6\(4\), 1.8.0\(55\), 1.8.1\(34\), 1.8.2\(11\), 1.8.3\(4\), 1.10.0

Timeline

Official Publish: August 8th, 2013
Last Modified: September 17th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.