Vulnerability Bulletins

Command Injection Vulnerability in Multiple Cisco TelePresence Products

   
Affected software Cisco
 
A vulnerability in the web framework of multiple CiscoTelePresence products could allow an authenticated, remote attacker to inject arbitrary commands that are executed with the privileges ofthe root user.The vulnerability is due to insufficient inputvalidation. An attacker could exploit this vulnerability byauthenticating to the device and submitting crafted input to theaffected parameter in a web page. Administrative privileges are requiredin order to access the affected parameter. A

More info:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150513-tp?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Command%20Injection%20Vulnerability%20in%20Multiple%20Cisco%20TelePresence%20Pr