CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:L/Au:S/C:C/I:C/A:C
AI Score
Confidence
Low
EPSS
Percentile
44.3%
The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to “command injection vulnerabilities,” aka Bug ID CSCtb31685.
Vendor | Product | Version | CPE |
---|---|---|---|
cisco | telepresence_system_software | 1.2.3 | cpe:2.3:a:cisco:telepresence_system_software:1.2.3:*:*:*:*:*:*:* |
cisco | telepresence_system_software | 1.3.2 | cpe:2.3:a:cisco:telepresence_system_software:1.3.2:*:*:*:*:*:*:* |
cisco | telepresence_system_software | 1.4.7 | cpe:2.3:a:cisco:telepresence_system_software:1.4.7:*:*:*:*:*:*:* |
cisco | telepresence_system_software | 1.5.1 | cpe:2.3:a:cisco:telepresence_system_software:1.5.1:*:*:*:*:*:*:* |
cisco | telepresence_system_software | 1.5.3 | cpe:2.3:a:cisco:telepresence_system_software:1.5.3:*:*:*:*:*:*:* |
cisco | telepresence_system_software | 1.5.10 | cpe:2.3:a:cisco:telepresence_system_software:1.5.10:*:*:*:*:*:*:* |
cisco | telepresence_system_software | 1.5.11 | cpe:2.3:a:cisco:telepresence_system_software:1.5.11:*:*:*:*:*:*:* |
cisco | telepresence_system_software | 1.5.12 | cpe:2.3:a:cisco:telepresence_system_software:1.5.12:*:*:*:*:*:*:* |
cisco | telepresence_system_software | 1.5.13 | cpe:2.3:a:cisco:telepresence_system_software:1.5.13:*:*:*:*:*:*:* |
cisco | telepresence_system_1000 | * | cpe:2.3:h:cisco:telepresence_system_1000:*:*:*:*:*:*:*:* |