← volver
CVE-2018-15430

Cisco Expressway Series and Cisco TelePresence Video Communication Server Remote Code Execution Vulnerability

EPSS 2.9%CWE-20
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS EPSS 2.9%KEV nãoPoC Nuclei Metasploit Patch referenciado
Ciclo de vida
05 oct 2018Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A vulnerability in the administrative web interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with user-level privileges on the underlying operating system. The vulnerability is due to insufficient validation of the content of upgrade packages. An attacker could exploit this vulnerability by uploading a malicious archive to the Upgrade page of the administrative web interface. A successful exploit could allow the attacker to execute code with user-level privileges on the underlying operating system.

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →