| Title | 複数の Cisco UVC System 製品における任意のコマンドを実行される脆弱性 |
|---|---|
| Summary | Cisco Unified Videoconferencing (UVC) System 5110 および 5115、Unified Videoconferencing System 3545 および 5230、Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway、Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway、Unified Videoconferencing 3515 Multipoint Control Unit (MCU) には、任意のコマンドを実行される脆弱性が存在します。 本脆弱性は、シェルコマンドインジェクションの脆弱性に関連し、Bug ID は CSCti54059 です。 |
| Possible impacts | リモート認証された管理者により、ユーザネームフィールドを介して、任意のコマンドを実行される可能性があります。 |
| Solution | ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date | Nov. 17, 2010, midnight |
| Registration Date | March 27, 2012, 6:42 p.m. |
| Last Update | March 27, 2012, 6:42 p.m. |
| CVSS2.0 : 危険 | |
| Score | 8.5 |
|---|---|
| Vector | AV:N/AC:M/Au:S/C:C/I:C/A:C |
| シスコシステムズ |
| unified videoconferencing system 3515 multipoint control unit |
| unified videoconferencing system 3522 basic rate interface gateway |
| unified videoconferencing system 3527 primary rate interface gateway |
| unified videoconferencing system 3545 |
| unified videoconferencing system 5110 |
| unified videoconferencing system 5115 |
| unified videoconferencing system 5230 |
| No | Changed Details | Date of change |
|---|---|---|
| 0 | [2012年03月27日] 掲載 |
Feb. 17, 2018, 10:37 a.m. |
| Summary | goform/websXMLAdminRequestCgi.cgi in Cisco Unified Videoconferencing (UVC) System 5110 and 5115, and possibly Unified Videoconferencing System 3545 and 5230, Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway, Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway, and Unified Videoconferencing 3515 Multipoint Control Unit (MCU), allows remote authenticated administrators to execute arbitrary commands via the username field, related to a "shell command injection vulnerability," aka Bug ID CSCti54059. |
|---|---|
| Publication Date | Nov. 23, 2010, 5 a.m. |
| Registration Date | Jan. 29, 2021, 11:04 a.m. |
| Last Update | Nov. 21, 2024, 10:17 a.m. |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:a:cisco:unified_videoconferencing_system_5110_firmware:7.0.1.13.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:cisco:unified_videoconferencing_system_5115_firmware:7.0.1.13.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:h:cisco:unified_videoconferencing_system_5110:*:*:*:*:*:*:*:* | |||||
| cpe:2.3:h:cisco:unified_videoconferencing_system_5115:*:*:*:*:*:*:*:* | |||||
| Configuration2 | or higher | or less | more than | less than | |
| cpe:2.3:a:cisco:unified_videoconferencing_system_3515_multipoint_control_unit_firmware:7.0.1.13.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:cisco:unified_videoconferencing_system_3522_basic_rate_interface_gateway_firmware:7.0.1.13.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:cisco:unified_videoconferencing_system_3527_primary_rate_interface_gateway_firmware:7.0.1.13.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:cisco:unified_videoconferencing_system_3545_firmware:7.0.1.13.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:cisco:unified_videoconferencing_system_5230_firmware:7.0.1.13.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:h:cisco:unified_videoconferencing_system_3515_multipoint_control_unit:*:*:*:*:*:*:*:* | |||||
| cpe:2.3:h:cisco:unified_videoconferencing_system_3522_basic_rate_interface_gateway:*:*:*:*:*:*:*:* | |||||
| cpe:2.3:h:cisco:unified_videoconferencing_system_3527_primary_rate_interface_gateway:*:*:*:*:*:*:*:* | |||||
| cpe:2.3:h:cisco:unified_videoconferencing_system_3545:*:*:*:*:*:*:*:* | |||||
| cpe:2.3:h:cisco:unified_videoconferencing_system_5230:*:*:*:*:*:*:*:* | |||||