Vulnslist

find the latest Cisco vulnerabilities

Cisco Hybrid Media Service Privilege Escalation Vulnerability

cisco-sa-20161207-hms · Medium · Published · Updated

A vulnerability in the installation procedure of the Cisco Hybrid Media Service could allow an authenticated, local attacker to elevate privileges to the root level. The vulnerability is due to incorrect installation and permissions settings on binary files during the Hybrid Media Service installation procedure. An attacker could exploit this vulnerability by logging in to the device and elevating privileges. A successful exploit could allow the attacker to acquire root-level privileges and take full control of the device. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161207-hms

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2016-6470
Cisco Bug IDsCSCvb81344
CVSS ScoreBase 6.8
Base 6.8 AV:L/AC:L/Au:S/C:C/I:C/A:C/E:F/RL:U/RC:C
Product Names From Source
Cisco Hybrid Meeting Server

Related Products

Product CVE Evidence