10
CVSSv2

CVE-2011-0382

Published: 25/02/2011 Updated: 09/04/2011
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The CGI subsystem on Cisco TelePresence Recording Server devices with software 1.6.x prior to 1.6.2 allows remote malicious users to execute arbitrary commands via a request to TCP port 443, related to a "command injection vulnerability," aka Bug ID CSCtf97221.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco telepresence recording server software 1.6.1

cisco telepresence recording server

Vendor Advisories

Multiple vulnerabilities exist within the Cisco TelePresence Recording Server This security advisory outlines details of the following vulnerabilities: Unauthenticated Java Servlet Access Common Gateway Interface (CGI) Command Injection Unauthenticated Arbitrary File Upload XML-Remote Procedure Call ...