Cisco TelePresence System Arbitrary Command Execution Vulnerability
BID:65071
Info
Cisco TelePresence System Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 65071 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-0661 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 22 2014 12:00AM |
| Updated: | Jan 28 2014 12:33AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco TelePresence System Arbitrary Command Execution Vulnerability
Cisco TelePresence System is prone to an arbitrary command-execution vulnerability.
Remote attackers can exploit this issue to execute arbitrary calls through stack corruption with the privilege of the root user.
This issue being tracked by Cisco Bug ID CSCui32796.
Cisco TelePresence System is prone to an arbitrary command-execution vulnerability.
Remote attackers can exploit this issue to execute arbitrary calls through stack corruption with the privilege of the root user.
This issue being tracked by Cisco Bug ID CSCui32796.
Exploit / POC
Cisco TelePresence System Arbitrary Command Execution Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Cisco TelePresence System Arbitrary Command Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cisco TelePresence System Arbitrary Command Execution Vulnerability
References:
References:
- Cisco Homepage (Cisco )