PT-2015-1963 · Cisco · Cisco Telepresence Video Communication Server

Publicado

2015-08-20

·

Atualizado

2017-01-04

·

CVE-2015-4328

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Cisco TelePresence Video Communication Server versions X8.5.2
Description The issue exists due to insufficient input validation in the software. It allows a remote attacker to execute arbitrary OS commands using a specially crafted HTTP request. This can be achieved by exploiting the improper checking of a user account's read-only attribute, enabling remote authenticated users to perform read or write operations on the Unified Communications lookup page.
Recommendations For version X8.5.2, consider restricting access to the Unified Communications lookup page until a patch is available. As a temporary workaround, limit the execution of arbitrary OS commands by restricting the use of crafted HTTP requests.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-11309
CVE-2015-4328

Produtos afetados

Cisco Telepresence Video Communication Server