CVE-2017-6794
published 2017-09-07CVE-2017-6794: A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to perform command injection and escalate…
PriorityP432medium6.7CVSS 3.0
AVLACLPRHUINSUCHIHAH
EPSS
0.84%
53.6th percentile
A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to perform command injection and escalate their privileges to root. The attacker must first authenticate to the application with valid administrator credentials. The vulnerability is due to insufficient validation of user-supplied input at the CLI for certain commands. An attacker could exploit this vulnerability by authenticating to the affected application and submitting a crafted CLI command for execution at the Cisco Meeting Server CLI. An exploit could allow the attacker to perform command injection and escalate their privilege level to root. Vulnerable Products: This vulnerability exists in Cisco Meeting Server software versions prior to and including 2.0, 2.1, and 2.2. Cisco Bug IDs: CSCvf53830.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
| cisco | meeting_server | — | — |
CVSS provenance
nvdv3.06.7MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6929-fmg8-wwgh: A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to perform command injection and
ghsa_unreviewed·2022-05-13
CVE-2017-6794 [HIGH] CWE-20 GHSA-6929-fmg8-wwgh: A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to perform command injection and
A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to perform command injection and escalate their privileges to root. The attacker must first authenticate to the application with valid administrator credentials. The vulnerability is due to insufficient validation of user-supplied input at the CLI for certain commands. An attacker could exploit this vulnerability by authenticating to the affected application and submitting a crafted CLI command for execution at the Cisco Meeting Server CLI. An exploit could allow the attacker to perform command injection and escalate their privilege level to root. Vulnerable Products: This vulnerability exists in Cisco Meeting Server software versions prior to and including 2.0, 2.1, and 2.2
Cisco
Cisco Meeting Server Command Injection and Privilege Escalation Vulnerability
vendor_cisco·2017-08-23·CVSS 6.7
CVE-2017-6794 [MEDIUM] CWE-20 Cisco Meeting Server Command Injection and Privilege Escalation Vulnerability
Cisco Meeting Server Command Injection and Privilege Escalation Vulnerability
A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to perform command injection and escalate their privileges to root. The attacker must first authenticate to the application with valid administrator credentials.
The vulnerability is due to insufficient validation of user-supplied input at the CLI for certain commands. An attacker could exploit this vulnerability by authenticating to the affected application and submitting a crafted CLI command for execution at the Cisco Meeting Server CLI. An exploit could allow the attacker to perform command injection and escalate their privilege level to root.
There are no workarounds that address this vulne
Cisco
Cisco Meeting Server Command Injection and Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-6794 Cisco Meeting Server Command Injection and Privilege Escalation Vulnerability
CVE-2017-6794: Cisco Meeting Server Command Injection and Privilege Escalation Vulnerability
A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to perform command injection and escalate their privileges to root . The attacker must first authenticate to the application with valid administrator credentials. The vulnerability is due to insufficient validation of user-supplied input at the CLI for certain commands. An attacker could exploit this vulnerability by authenticating to the affected application and submitting a crafted CLI command for execution at the Cisco Meeting Server CLI. An exploit could allow the attacker to perform command injection and escalate their privilege level to root . There are no
CVSS: 3.0
CWE: CWE-20
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/100464http://www.securitytracker.com/id/1039245https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170823-cmshttp://www.securityfocus.com/bid/100464http://www.securitytracker.com/id/1039245https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170823-cms
2017-09-07
Published