CVE-2012-2486 describes a critical vulnerability in the Cisco Discovery Protocol (CDP) implementation across several Cisco TelePresence products, including Multipoint Switch, Immersive Endpoint Devices, Manager, and Recording Server, all in versions prior to 1.9.0 or 1.8.1. This flaw allows remote attackers to execute arbitrary code by sending a specially crafted, malformed CDP packet to an adjacent device. With a CVSS score of 8.3, this vulnerability is highly severe, requiring adjacent network access but no authentication, and could lead to complete compromise of confidentiality, integrity, and availability. Despite its severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.8.3\(9\)CPE matchmatch criteria | cpe:2.3:a:cisco:telepresence_multipoint_switch_software:*:*:*:*:*:*:*:* | ||
1.0.4.0CPE matchmatch criteria | cpe:2.3:a:cisco:telepresence_multipoint_switch_software:1.0.4.0:*:*:*:*:*:*:* | ||
1.0.4.0\(21\)CPE matchmatch criteria | cpe:2.3:a:cisco:telepresence_multipoint_switch_software:1.0.4.0\(21\):*:*:*:*:*:*:* | ||
1.1.0CPE matchmatch criteria | cpe:2.3:a:cisco:telepresence_multipoint_switch_software:1.1.0:*:*:*:*:*:*:* | ||
1.1.0\(254\)CPE matchmatch criteria | cpe:2.3:a:cisco:telepresence_multipoint_switch_software:1.1.0\(254\):*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:A/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.