Cisco Video Communications Server (VCS) before X7.0.3 contains a command injection vulnerability which allows remote, authenticated attackers to execute arbitrary commands.
References
Link | Resource |
---|---|
https://www.cisco.com/c/dam/en/us/td/docs/telepresence/infrastructure/vcs/release_note/Cisco_VCS_Release_Note_X7-0-3.pdf | Vendor Advisory |
Configurations
Information
Published : 2019-10-29 12:15
Updated : 2019-11-01 11:17
NVD link : CVE-2011-2538
Mitre link : CVE-2011-2538
JSON object : View
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Products Affected
cisco
- telepresence_video_communication_server