Cisco TelePresence Supervisor MSE 8050 Multiple Vulnerabilities in OpenSSL

Medium Nessus Plugin ID 76132


The remote host is affected by multiple vulnerabilities.


The remote Cisco TelePresence device is running a software version known to be affected by multiple OpenSSL related vulnerabilities :

- An unspecified error exists that could allow an attacker to cause usage of weak keying material leading to simplified man-in-the-middle attacks.

- An unspecified error exists related to anonymous ECDH ciphersuites that could allow denial of service attacks. Note this issue only affects OpenSSL TLS clients. (CVE-2014-3470)


There is currently no known solution.

See Also

Plugin Details

Severity: Medium

ID: 76132

File Name: cisco_telepresence_supervisor_8050_mse_CSCup22635.nasl

Version: 1.7

Type: remote

Family: CISCO

Published: 2014/06/18

Updated: 2019/11/26

Dependencies: 76125

Risk Information

Risk Factor: Medium

CVSS Score Source: CVE-2014-0224

CVSS v2.0

Base Score: 5.8

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N

Temporal Vector: CVSS2#E:F/RL:U/RC:C

Vulnerability Information

CPE: cpe:/h:cisco:telepresence_supervisor_mse_8050

Required KB Items: cisco/supervisor_mse/8050

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2014/06/05

Vulnerability Publication Date: 2014/06/05

Exploitable With

Core Impact

Reference Information

CVE: CVE-2014-0224, CVE-2014-3470

BID: 67898, 67899

CERT: 978508