Lucene search

K
ciscoCiscoCISCO-SA-20150513-TP
HistoryMay 13, 2015 - 4:00 p.m.

Command Injection Vulnerability in Multiple Cisco TelePresence Products

2015-05-1316:00:00
tools.cisco.com
11

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

EPSS

0.002

Percentile

52.1%

A vulnerability in the web framework of multiple Cisco
TelePresence products could allow an authenticated, remote attacker to inject arbitrary commands that are executed with the privileges of
the root user.

The vulnerability is due to insufficient input
validation. An attacker could exploit this vulnerability by
authenticating to the device and submitting crafted input to the
affected parameter in a web page. Administrative privileges are required
in order to access the affected parameter. A successful exploit could allow an
attacker
to execute system commands with the privileges of the root user.

Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This advisory is available at the following link:

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150513-tp[“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150513-tp”]

Affected configurations

Vulners
Node
ciscotelepresence_server_softwareMatchany
OR
ciscotelepresence_mcu_softwareMatchany
OR
ciscotelepresence_supervisor_mse_8050_softwareMatchany
OR
ciscotelepresence_isdn_gw_3241Matchany
OR
ciscotelepresence_advanced_media_gatewayMatchany
OR
ciscotelepresence_ip_gatewayMatchany
OR
ciscotelepresence_serial_gatewayMatchany
OR
ciscotelepresence_ip_vcr_2.4Matchany
OR
ciscotelepresence_server_softwareMatchany
OR
ciscotelepresence_mcu_softwareMatchany
OR
ciscotelepresence_supervisor_mse_8050Match8050_software
OR
ciscotelepresence_isdn_gw_3241Match3241
OR
ciscotelepresence_advanced_media_gatewayMatchany
OR
ciscotelepresence_ip_gatewayMatchany
OR
ciscotelepresence_serial_gatewayMatchany
OR
ciscotelepresence_ip_vcr_2.4Matchany
VendorProductVersionCPE
ciscotelepresence_server_softwareanycpe:2.3:a:cisco:telepresence_server_software:any:*:*:*:*:*:*:*
ciscotelepresence_mcu_softwareanycpe:2.3:a:cisco:telepresence_mcu_software:any:*:*:*:*:*:*:*
ciscotelepresence_supervisor_mse_8050_softwareanycpe:2.3:a:cisco:telepresence_supervisor_mse_8050_software:any:*:*:*:*:*:*:*
ciscotelepresence_isdn_gw_3241anycpe:2.3:a:cisco:telepresence_isdn_gw_3241:any:*:*:*:*:*:*:*
ciscotelepresence_advanced_media_gatewayanycpe:2.3:a:cisco:telepresence_advanced_media_gateway:any:*:*:*:*:*:*:*
ciscotelepresence_ip_gatewayanycpe:2.3:a:cisco:telepresence_ip_gateway:any:*:*:*:*:*:*:*
ciscotelepresence_serial_gatewayanycpe:2.3:a:cisco:telepresence_serial_gateway:any:*:*:*:*:*:*:*
ciscotelepresence_ip_vcr_2.4anycpe:2.3:a:cisco:telepresence_ip_vcr_2.4:any:*:*:*:*:*:*:*
ciscotelepresence_supervisor_mse_80508050_softwarecpe:2.3:h:cisco:telepresence_supervisor_mse_8050:8050_software:*:*:*:*:*:*:*
ciscotelepresence_isdn_gw_32413241cpe:2.3:a:cisco:telepresence_isdn_gw_3241:3241:*:*:*:*:*:*:*

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

EPSS

0.002

Percentile

52.1%