CVE-2016-6459
published 2016-11-19CVE-2016-6459: Cisco TelePresence endpoints running either CE or TC software contain a vulnerability that could allow an authenticated, local attacker to execute a local…
PriorityP425medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.74%
50.3th percentile
Cisco TelePresence endpoints running either CE or TC software contain a vulnerability that could allow an authenticated, local attacker to execute a local shell command injection. More Information: CSCvb25010. Known Affected Releases: 8.1.x. Known Fixed Releases: 6.3.4 7.3.7 8.2.2 8.3.0.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_endpoints_local | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:C/I:N/A:N
vendor_cisco4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j33x-pv47-v562: Cisco TelePresence endpoints running either CE or TC software contain a vulnerability that could allow an authenticated, local attacker to execute a l
ghsa_unreviewed·2022-05-17
CVE-2016-6459 [MEDIUM] CWE-78 GHSA-j33x-pv47-v562: Cisco TelePresence endpoints running either CE or TC software contain a vulnerability that could allow an authenticated, local attacker to execute a l
Cisco TelePresence endpoints running either CE or TC software contain a vulnerability that could allow an authenticated, local attacker to execute a local shell command injection. More Information: CSCvb25010. Known Affected Releases: 8.1.x. Known Fixed Releases: 6.3.4 7.3.7 8.2.2 8.3.0.
Cisco
Cisco TelePresence Endpoints Local Command Injection Vulnerability
vendor_cisco·2016-11-02·CVSS 4.6
CVE-2016-6459 [MEDIUM] CWE-78 Cisco TelePresence Endpoints Local Command Injection Vulnerability
Cisco TelePresence Endpoints Local Command Injection Vulnerability
Cisco TelePresence endpoints running either CE or TC software contain a vulnerability that could allow an authenticated, local attacker to execute a local shell command injection.
The vulnerability is due to incomplete input sanitization of some commands. An attacker could exploit this vulnerability by executing local shell commands with commands injected as parameters. An exploit could allow the attacker to retrieve full information from the device including private keys.
Cisco has not released software updates that address this vulnerability. Workarounds that address this vulnerability are not available.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecu
Cisco
Cisco TelePresence Endpoints Local Command Injection Vulnerability
vendor_cisco
CVE-2016-6459 Cisco TelePresence Endpoints Local Command Injection Vulnerability
CVE-2016-6459: Cisco TelePresence Endpoints Local Command Injection Vulnerability
Cisco TelePresence endpoints running either CE or TC software contain a vulnerability that could allow an authenticated, local attacker to execute a local shell command injection. The vulnerability is due to incomplete input sanitization of some commands. An attacker could exploit this vulnerability by executing local shell commands with commands injected as parameters. An exploit could allow the attacker to retrieve full information from the device including private keys. Cisco has not released software updates that address this vulnerability.
CWE: CWE-78, CWE-78
Bug IDs: CSCvb25010
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/94075http://www.securitytracker.com/id/1037187https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161102-tphttp://www.securityfocus.com/bid/94075http://www.securitytracker.com/id/1037187https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161102-tp
2016-11-19
Published