Cisco Video Communications Server (VCS) before X7.0.3 contains a command injection vulnerability which allows remote, authenticated attackers to execute arbitrary commands.
References
Link | Resource |
---|---|
https://www.cisco.com/c/dam/en/us/td/docs/telepresence/infrastructure/vcs/release_note/Cisco_VCS_Release_Note_X7-0-3.pdf | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2019-10-29 19:15
Updated : 2024-02-28 17:28
NVD link : CVE-2011-2538
Mitre link : CVE-2011-2538
CVE.ORG link : CVE-2011-2538
JSON object : View
Products Affected
cisco
- telepresence_video_communication_server
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')