← Vulnerability feed

Vulnerability record · CVE-2011-0384 · published 25 February 2011

CVE-2011-0384: Cisco telepresence multipoint switch software improper authentication vulnerability

Cisco · Telepresence Multipoint Switch Software

The Java Servlet framework on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x does not require administrative authentication for unspecified actions, which allows remote attackers to execute arbitrary code via a crafted request, aka Bug ID CSCtf01253.

10.0 CVSS 2.0 High EPSS 5.9% · top 7.0% CWE-287 · Improper authentication
10.0CVSS 2.0 base score
5.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

The Java Servlet framework on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x does not require administrative authentication for unspecified actions, which allows remote attackers to execute arbitrary code via a crafted request, aka Bug ID CSCtf01253.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-0384 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-0383Cisco telepresence recording server software improper authentication vulnerabilityThe Java Servlet framework on Cisco TelePresence Recording Server devices with software 1.6.x before 1.6.2 and Cisco TelePresence Multipoint Switch (…EPSS 6.5%10.0CVE-2011-0385Cisco telepresence recording server software vulnerabilityThe administrative web interface on Cisco TelePresence Recording Server devices with software 1.6.x and Cisco TelePresence Multipoint Switch (CTMS) d…EPSS 5.2%8.3CVE-2012-2486Cisco telepresence multipoint switch software code injection vulnerabilityThe Cisco Discovery Protocol (CDP) implementation on Cisco TelePresence Multipoint Switch before 1.9.0, Cisco TelePresence Immersive Endpoint Devices…EPSS 1.7%8.0CVE-2011-0387Cisco telepresence multipoint switch software permissions and access controls vulnerabilityThe administrative web interface on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x allows remote au…EPSS 2.0%7.9CVE-2011-0379Cisco adaptive security appliance software memory buffer overflow vulnerabilityBuffer overflow on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 1.6.x; Cisco TelePresence Multipoint Switch (CTMS) devi…EPSS 2.2%7.8CVE-2012-3073Cisco telepresence multipoint switch software vulnerabilityThe IP implementation on Cisco TelePresence Multipoint Switch before 1.8.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording…EPSS 1.8%7.8CVE-2011-0390Cisco telepresence multipoint switch software vulnerabilityThe XML-RPC implementation on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, 1.6.x, and 1.7.0 allows remote a…EPSS 2.6%7.8CVE-2011-0388Cisco telepresence recording server software vulnerabilityCisco TelePresence Recording Server devices with software 1.6.x and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1…EPSS 2.6%

Source: NIST National Vulnerability Database (record CVE-2011-0384), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.