Vulnslist

find the latest Cisco vulnerabilities

Cisco Desktop Collaboration Experience DX600 Series Potential Code Injection Vulnerability

Cisco-SA-20130701-CVE-2013-3399 · Medium · Published · Updated

A vulnerability in an underlying Android Application Programming Interface (API) utilized by the Cisco Desktop Collaboration Experience DX600 series endpoint could allow an authenticated, local attacker to inject code into the system. The vulnerability is due to insufficient validation of specific values prior to their use to allocate a buffer. An attacker could exploit this vulnerability by overflowing a buffer. An exploit could allow the attacker to execute arbitrary code with elevated privileges. Cisco has confirmed this vulnerability in a security notice and released software updates. To successfully exploit the vulnerability, the attacker would need to authenticate and have local access to the targeted system, which could limit the likelihood of an exploit.

Workarounds

Administrators are advised to apply the appropriate updates.

Administrators are advised to allow only trusted users to access local systems.

Administrators are advised to apply the appropriate updates.

CVEsCVE-2013-3399
Cisco Bug IDsCSCuf93957, CSCug22352, CSCug22462
CVSS ScoreBase 6.0
Base 6.0 AV:L/AC:H/Au:S/C:C/I:C/A:C/E:POC/RL:OF/RC:C
Product Names From Source
Cisco Desktop Collaboration Experience DX650 Software

Related Products

Product CVE Evidence