Vulnslist

find the latest Cisco vulnerabilities

Command Injection Vulnerability in Multiple Cisco TelePresence Products

cisco-sa-20150513-tp · Critical · Published · Updated

A vulnerability in the web framework of multiple Cisco TelePresence products could allow an authenticated, remote attacker to inject arbitrary commands that are executed with the privileges of the root user. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by authenticating to the device and submitting crafted input to the affected parameter in a web page. Administrative privileges are required in order to access the affected parameter. A successful exploit could allow an attacker to execute system commands with the privileges of the root user. Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150513-tp

Cisco advisory · CSAF JSON

Workarounds

There is no workaround for this vulnerability.

CVEsCVE-2015-0713
Cisco Bug IDsCSCul55968, CSCur08993, CSCur15803, CSCur15807, CSCur15825, CSCur15832, CSCur15842, CSCur15850, CSCur15855
CVSS ScoreBase 9.0
Base 9.0 AV:N/AC:L/Au:S/C:C/I:C/A:C/E:F/RL:OF/RC:C
Product Names From Source
Cisco TelePresence Server Software, Cisco TelePresence MCU Software, Cisco TelePresence Supervisor MSE 8050 Software, Cisco TelePresence ISDN GW 3241, Cisco TelePresence Advanced Media Gateway, Cisco TelePresence IP Gateway Series, Cisco TelePresence Serial Gateway Series, Cisco TelePresence IP VCR Series, Cisco TelePresence Server

Related Products

Product CVE Evidence
Cisco TelePresence Supervisor MSE 8050 Software CVE-2015-0713 Cisco OpenVuln
Cisco TelePresence Server Software CVE-2015-0713 Cisco OpenVuln
Cisco TelePresence Server CVE-2015-0713 Cisco OpenVuln
Cisco TelePresence Serial Gateway Series CVE-2015-0713 Cisco OpenVuln
Cisco TelePresence MCU Software CVE-2015-0713 Cisco OpenVuln
Cisco TelePresence ISDN GW 3241 CVE-2015-0713 Cisco OpenVuln
Cisco TelePresence IP VCR Series CVE-2015-0713 Cisco OpenVuln
Cisco TelePresence IP Gateway Series CVE-2015-0713 Cisco OpenVuln
Cisco TelePresence Advanced Media Gateway CVE-2015-0713 Cisco OpenVuln
Cisco TelePresence CVE-2015-0713 Cisco OpenVuln