Lucene search

K
nvd[email protected]NVD:CVE-2019-7632
HistoryFeb 08, 2019 - 5:29 a.m.

CVE-2019-7632

2019-02-0805:29:01
CWE-78
web.nvd.nist.gov
3

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9

Confidence

High

EPSS

0.003

Percentile

70.3%

LifeSize Team, Room, Passport, and Networker 220 devices allow Authenticated Remote OS Command Injection, as demonstrated by shell metacharacters in the support/mtusize.php mtu_size parameter. The lifesize default password for the cli account may sometimes be used for authentication.

Affected configurations

Nvd
Node
lifesizeteam_220_firmwareMatch-
AND
lifesizeteam_220Match-
Node
lifesizepassport_220_firmwareMatch-
AND
lifesizepassport_220Match-
Node
lifesizenetworker_220_firmwareMatch-
AND
lifesizenetworker_220Match-
Node
lifesizeroom_220_firmwareMatch-
AND
lifesizeroom_220Match-
VendorProductVersionCPE
lifesizeteam_220_firmware-cpe:2.3:o:lifesize:team_220_firmware:-:*:*:*:*:*:*:*
lifesizeteam_220-cpe:2.3:h:lifesize:team_220:-:*:*:*:*:*:*:*
lifesizepassport_220_firmware-cpe:2.3:o:lifesize:passport_220_firmware:-:*:*:*:*:*:*:*
lifesizepassport_220-cpe:2.3:h:lifesize:passport_220:-:*:*:*:*:*:*:*
lifesizenetworker_220_firmware-cpe:2.3:o:lifesize:networker_220_firmware:-:*:*:*:*:*:*:*
lifesizenetworker_220-cpe:2.3:h:lifesize:networker_220:-:*:*:*:*:*:*:*
lifesizeroom_220_firmware-cpe:2.3:o:lifesize:room_220_firmware:-:*:*:*:*:*:*:*
lifesizeroom_220-cpe:2.3:h:lifesize:room_220:-:*:*:*:*:*:*:*

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9

Confidence

High

EPSS

0.003

Percentile

70.3%

Related for NVD:CVE-2019-7632