CVE-2016-1468
published 2016-08-08CVE-2016-1468: The administrative web interface in Cisco TelePresence Video Communication Server Expressway X8.5.2 allows remote authenticated users to execute arbitrary…
PriorityP357high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
2.89%
85.3th percentile
The administrative web interface in Cisco TelePresence Video Communication Server Expressway X8.5.2 allows remote authenticated users to execute arbitrary commands via crafted fields, aka Bug ID CSCuv12531.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_video_communication_server | — | — |
| cisco | telepresence_video_communication_server_expressway | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco TelePresence Video Communication Server Expressway Command Injection Vulnerability
vendor_cisco·2016-08-03·CVSS 6.0
CVE-2016-1468 [MEDIUM] CWE-78 Cisco TelePresence Video Communication Server Expressway Command Injection Vulnerability
Cisco TelePresence Video Communication Server Expressway Command Injection Vulnerability
A vulnerability in the administrative web interface of Cisco TelePresence Video Communication Server Expressway could allow an authenticated, remote attacker to execute arbitrary commands on the affected system.
The vulnerability is due to the failure to properly sanitize user input passed to the affected system's scripts. An attacker could exploit this vulnerability by submitting crafted input to the affected fields of the web interface. Successful exploitation of this vulnerability could allow an attacker to run arbitrary commands on the system.
Cisco has released software updates that address this vulnerability. Workarounds that address this vulnerability are not available.
This advisory is ava
Cisco
Cisco TelePresence Video Communication Server Expressway Command Injection Vulnerability
vendor_cisco
CVE-2016-1468 Cisco TelePresence Video Communication Server Expressway Command Injection Vulnerability
CVE-2016-1468: Cisco TelePresence Video Communication Server Expressway Command Injection Vulnerability
A vulnerability in the administrative web interface of Cisco TelePresence Video Communication Server Expressway could allow an authenticated, remote attacker to execute arbitrary commands on the affected system. The vulnerability is due to the failure to properly sanitize user input passed to the affected system's scripts. An attacker could exploit this vulnerability by submitting crafted input to the affected fields of the web interface. Successful exploitation of this vulnerability could allow an attacker to run arbitrary commands on the system. Cisco has released software updates that address this vulnerability.
CWE: CWE-78, CWE-78
Bug IDs: CSCuv12531
GHSA
GHSA-39fg-mxcp-4qr2: The administrative web interface in Cisco TelePresence Video Communication Server Expressway X8
ghsa_unreviewed·2022-05-17
CVE-2016-1468 [HIGH] CWE-78 GHSA-39fg-mxcp-4qr2: The administrative web interface in Cisco TelePresence Video Communication Server Expressway X8
The administrative web interface in Cisco TelePresence Video Communication Server Expressway X8.5.2 allows remote authenticated users to execute arbitrary commands via crafted fields, aka Bug ID CSCuv12531.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160803-vcsehttp://www.securityfocus.com/bid/92274http://www.securitytracker.com/id/1036529http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160803-vcsehttp://www.securityfocus.com/bid/92274http://www.securitytracker.com/id/1036529
2016-08-08
Published