CVE-2011-0392
CVE-2011-0392 is a high-severity vulnerability in Cisco Telepresence Recording Server Software with a CVSS 2.0 base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-287.
Key facts
- Severity: High (CVSS 2.0 base score 7.5)
- EPSS exploit prediction: 2% (83rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-287
- Affected product: Cisco Telepresence Recording Server Software
- Published:
- Last modified:
Description
Cisco TelePresence Recording Server devices with software 1.6.x do not require authentication for an XML-RPC interface, which allows remote attackers to perform unspecified actions via a session on TCP port 8080, aka Bug ID CSCtg35833.
Frequently asked questions
- What is CVE-2011-0392?
- Cisco TelePresence Recording Server devices with software 1.6.x do not require authentication for an XML-RPC interface, which allows remote attackers to perform unspecified actions via a session on TCP port 8080, aka Bug ID CSCtg35833.
- How severe is CVE-2011-0392?
- CVE-2011-0392 has a CVSS 2.0 base score of 7.5, rated high severity.
- Is CVE-2011-0392 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (83rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2011-0392?
- CVE-2011-0392 primarily affects Cisco Telepresence Recording Server Software. In total, 4 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2011-0392?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2011-0392 published?
- CVE-2011-0392 was published on 2011-02-25 and last updated on 2026-06-16.
References
- http://www.cisco.com/en/US/products/products_security_advisory09186a0080b6e11d.shtml
- http://www.securityfocus.com/bid/46522
- http://www.securitytracker.com/id?1025114
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65609
Affected products (4)
- cpe:2.3:a:cisco:telepresence_recording_server_software:1.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:telepresence_recording_server_software:1.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:cisco:telepresence_recording_server_software:1.6.3:*:*:*:*:*:*:*
- cpe:2.3:h:cisco:telepresence_recording_server:*:*:*:*:*:*:*:*
More vulnerabilities in Cisco Telepresence Recording Server Software
- CVE-2011-2555 — Critical (CVSS 10.0): Cisco TelePresence Recording Server 1.7.2.x before 1.7.2.1 has a default password for the root administrator account,…
- CVE-2011-0385 — Critical (CVSS 10.0): The administrative web interface on Cisco TelePresence Recording Server devices with software 1.6.x and Cisco…
- CVE-2011-0383 — Critical (CVSS 10.0): The Java Servlet framework on Cisco TelePresence Recording Server devices with software 1.6.x before 1.6.2 and Cisco…
- CVE-2011-0382 — Critical (CVSS 10.0): The CGI subsystem on Cisco TelePresence Recording Server devices with software 1.6.x before 1.6.2 allows remote…
- CVE-2011-0386 — Critical (CVSS 9.3): The XML-RPC implementation on Cisco TelePresence Recording Server devices with software 1.6.x and 1.7.x before 1.7.1…
- CVE-2011-0391 — High (CVSS 7.8): Cisco TelePresence Recording Server devices with software 1.6.x allow remote attackers to cause a denial of service…
All CVEs affecting Cisco Telepresence Recording Server Software →
Other CWE-287 (Improper Authentication) vulnerabilities
- CVE-2026-101077 — Critical (CVSS 10.0): A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp…
- CVE-2026-100886 — Critical (CVSS 10.0): A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected…
- CVE-2026-77244 — Critical (CVSS 10.0): MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0,…
- CVE-2026-94493 — Critical (CVSS 10.0): A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of…
- CVE-2026-83099 — Critical (CVSS 10.0): Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).…
- CVE-2026-83059 — Critical (CVSS 10.0): Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server).…
Browse all CWE-287 (Improper Authentication) vulnerabilities →