7 results (0.041 seconds)

CVSS: 4.9EPSS: 0%CPEs: 5EXPL: 0

/opt/rv/Versions/CurrentVersion/Mcu/Config/Mcu.val in Cisco Unified Videoconferencing (UVC) System 5110 and 5115, when the Linux operating system is used, uses a weak hashing algorithm for the (1) administrator and (2) operator passwords, which makes it easier for local users to obtain sensitive information by recovering the cleartext values, aka Bug ID CSCti54010. /opt/rv/Versions/CurrentVersion/Mcu/Config/Mcu.val en Cisco Unified Videoconferencing (UVC) System 5110 y 5115, cuando se usa Linux, utiliza un algoritmo débil de para calcular el resumen (hash) de las contraseñas de (1) administrador y (2) operador, lo que facilita a usuarios locales obtener información sensible recuperando valores en texto claro, también conocido como error ID CSCti54010. • http://seclists.org/fulldisclosure/2010/Nov/167 http://www.cisco.com/en/US/products/products_security_response09186a0080b56d0d.html http://www.trustmatta.com/advisories/MATTA-2010-001.txt • CWE-310: Cryptographic Issues •

CVSS: 6.4EPSS: 0%CPEs: 14EXPL: 0

The web interface in Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115, and 5230; Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway; Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway; and Unified Videoconferencing 3515 Multipoint Control Unit (MCU) uses predictable session IDs based on time values, which makes it easier for remote attackers to hijack sessions via a brute-force attack, aka Bug ID CSCti54048. La interfaz Web de las herramientas de Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115 y 5230; Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway; Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway; y Unified Videoconferencing 3515 Multipoint Control Unit (MCU) utilizan identificadores de sesión predecibles basados en valores de tiempo, lo que facilita a los atacantes remotos a la hora de secuestrar sesiones a través de un ataque de fuerza bruta. El fallo tiene el ID interno CSCti54048. • http://seclists.org/fulldisclosure/2010/Nov/167 http://www.cisco.com/en/US/products/products_security_response09186a0080b56d0d.html http://www.trustmatta.com/advisories/MATTA-2010-001.txt • CWE-310: Cryptographic Issues •

CVSS: 4.9EPSS: 0%CPEs: 5EXPL: 0

Cisco Unified Videoconferencing (UVC) System 5110 and 5115, when the Linux operating system is used, uses world-readable permissions for the /etc/shadow file, which allows local users to discover encrypted passwords by reading this file, aka Bug ID CSCti54043. El Sistema Cisco Unified Videoconferencing (UVC) 5110 y 5115, cuando se utiliza en Sistemas Operativos Linux emplea permisos de lectura para todos (world-readable) para el fichero /etc/shadow, esto permite a usuarios locales descubrir las contraseñas cifradas al leer este fichero. También se conoce como Bug ID CSCti54043. • http://seclists.org/fulldisclosure/2010/Nov/167 http://www.cisco.com/en/US/products/products_security_response09186a0080b56d0d.html http://www.trustmatta.com/advisories/MATTA-2010-001.txt • CWE-255: Credentials Management Errors •

CVSS: 5.0EPSS: 0%CPEs: 14EXPL: 0

Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115, and 5230; Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway; Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway; and Unified Videoconferencing 3515 Multipoint Control Unit (MCU) improperly use cookies for web-interface credentials, which allows remote attackers to obtain sensitive information by reading a (1) cleartext or (2) base64-encoded cleartext cookie, aka Bug ID CSCti54052. Los sistemas Cisco Unified Videoconferencing (UVC) 3545, 5110, 5115, y 5230; Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway; Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway; y Unified Videoconferencing 3515 Multipoint Control Unit (MCU) utilizan las cookies para las credenciales del interfase web de forma inadecuada, lo que permite a atacantes remotos obtener información sensible leyendo una cookie en (1) texto claro o (2) texto claro codificado en base64, también conocido como error ID CSCti54052. • http://seclists.org/fulldisclosure/2010/Nov/167 http://www.cisco.com/en/US/products/products_security_response09186a0080b56d0d.html http://www.trustmatta.com/advisories/MATTA-2010-001.txt • CWE-310: Cryptographic Issues •

CVSS: 8.5EPSS: 0%CPEs: 14EXPL: 0

goform/websXMLAdminRequestCgi.cgi in Cisco Unified Videoconferencing (UVC) System 5110 and 5115, and possibly Unified Videoconferencing System 3545 and 5230, Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway, Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway, and Unified Videoconferencing 3515 Multipoint Control Unit (MCU), allows remote authenticated administrators to execute arbitrary commands via the username field, related to a "shell command injection vulnerability," aka Bug ID CSCti54059. goform/websXMLAdminRequestCgi.cgi en Cisco Unified Videoconferencing (UVC) System 5110 y 5115, y posiblemente Unified Videoconferencing System3545 y 5230, Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway, Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway, and Unified Videoconferencing 3515 Multipoint Control Unit (MCU), permite a administradores remotos autenticados ejecutar comandos de su elección a través del campo 'username', relacionado con vulnerabilidad de inyección de comando shell (shell command injection vulnerability), también conocido como "Bug ID CSCti54059". • http://seclists.org/fulldisclosure/2010/Nov/167 http://www.cisco.com/en/US/products/products_security_response09186a0080b56d0d.html http://www.securityfocus.com/bid/44922 http://www.securitytracker.com/id?1024753 http://www.trustmatta.com/advisories/MATTA-2010-001.txt • CWE-94: Improper Control of Generation of Code ('Code Injection') •