9
CVSSv2

CVE-2019-7632

Published: 08/02/2019 Updated: 08/02/2019
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

LifeSize Team, Room, Passport, and Networker 220 devices allow Authenticated Remote OS Command Injection, as demonstrated by shell metacharacters in the support/mtusize.php mtu_size parameter. The lifesize default password for the cli account may sometimes be used for authentication.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lifesize team_220_firmware -

lifesize passport_220_firmware -

lifesize networker_220_firmware -

lifesize room_220_firmware -