4

CVE-2015-4328

Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 improperly checks for a user account's read-only attribute, which allows remote authenticated users to execute arbitrary OS commands via crafted HTTP requests, as demonstrated by read or write operations on the Unified Communications lookup page, aka Bug ID CSCuv12552.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Telepresence Video Communication Server Software Version x8.5.2 SwEdition expressway
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.98% 0.78
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://tools.cisco.com/security/center/viewAlert.x?alertId=40522
Vendor Advisory
http://www.securityfocus.com/bid/76399
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1033329
Third Party Advisory
VDB Entry