Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-34715

Опубликовано: 18 авг. 2021
Источник: nvd
CVSS3: 4.7
CVSS3: 7.2
CVSS2: 9
EPSS Низкий

Описание

A vulnerability in the image verification function of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with internal user privileges on the underlying operating system. The vulnerability is due to insufficient validation of the content of upgrade packages. An attacker could exploit this vulnerability by uploading a malicious archive to the Upgrade page of the administrative web interface. A successful exploit could allow the attacker to execute code with user-level privileges (the _nobody account) on the underlying operating system.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:expressway:*:*:*:*:*:*:*:*
Версия до x8.8.0 (включая)
cpe:2.3:a:cisco:telepresence_video_communication_server:*:*:*:*:*:*:*:*
Версия до x8.8 (включая)

EPSS

Процентиль: 71%
0.00669
Низкий

4.7 Medium

CVSS3

7.2 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-347
CWE-347

Связанные уязвимости

github
больше 3 лет назад

A vulnerability in the image verification function of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with internal user privileges on the underlying operating system. The vulnerability is due to insufficient validation of the content of upgrade packages. An attacker could exploit this vulnerability by uploading a malicious archive to the Upgrade page of the administrative web interface. A successful exploit could allow the attacker to execute code with user-level privileges (the _nobody account) on the underlying operating system.

CVSS3: 7.2
fstec
больше 4 лет назад

Уязвимость функции проверки образов ПО устройств управления конференц-связью Cisco Expressway Series и Cisco Telepresence VCS, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 71%
0.00669
Низкий

4.7 Medium

CVSS3

7.2 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-347
CWE-347