Lucene search

K
ciscoCiscoCISCO-SA-20150715-CVE-2015-4276
HistoryJul 15, 2015 - 9:24 p.m.

Cisco WebEx Meetings Server Remote Code Execution Vulnerability

2015-07-1521:24:39
tools.cisco.com
20

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

EPSS

0.005

Percentile

76.0%

A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to execute arbitrary code on a targeted system.

The vulnerability is due to insufficient sanitization of user-supplied input. An attacker could exploit this vulnerability by sending crafted data in a command parameter to an affected system. A successful exploit could allow the attacker to execute arbitrary code on the affected system, which could be leveraged to conduct further attacks.

Cisco has confirmed the vulnerability and released software updates.

To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requirement reduces the likelihood of a successful exploit.

Affected configurations

Vulners
Node
ciscowebex_meetings_serverMatchany
OR
ciscowebex_meetings_serverMatchany
VendorProductVersionCPE
ciscowebex_meetings_serveranycpe:2.3:a:cisco:webex_meetings_server:any:*:*:*:*:*:*:*

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

EPSS

0.005

Percentile

76.0%

Related for CISCO-SA-20150715-CVE-2015-4276