CVE-2011-4659

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
19/01/2012
Last modified:
11/04/2025

Description

Cisco TelePresence Software before TE 4.1.1 on the Cisco IP Video Phone E20 has a default password for the root account after an upgrade to TE 4.1.0, which makes it easier for remote attackers to modify the configuration via an SSH session, aka Bug ID CSCtw69889, a different vulnerability than CVE-2011-2555.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cisco:telepresence_e20_software:*:*:*:*:*:*:*:* te4.1.1-cucm (including)
cpe:2.3:a:cisco:telepresence_e20_software:te2.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:telepresence_e20_software:te2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:telepresence_e20_software:te4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:telepresence_e20_software:te4.1.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:telepresence_e20_software:te4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:telepresence_e20_software:tenc4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:telepresence_e20_software:tenc4.1.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:telepresence_e20_software:tenc4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:telepresence_e20_software:tenc4.1.1-cucm:*:*:*:*:*:*:*
cpe:2.3:h:cisco:ip_video_phone_e20:-:*:*:*:*:*:*:*