3 results (0.011 seconds)

CVSS: 6.4EPSS: 0%CPEs: 14EXPL: 0

The web interface in Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115, and 5230; Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway; Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway; and Unified Videoconferencing 3515 Multipoint Control Unit (MCU) uses predictable session IDs based on time values, which makes it easier for remote attackers to hijack sessions via a brute-force attack, aka Bug ID CSCti54048. La interfaz Web de las herramientas de Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115 y 5230; Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway; Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway; y Unified Videoconferencing 3515 Multipoint Control Unit (MCU) utilizan identificadores de sesión predecibles basados en valores de tiempo, lo que facilita a los atacantes remotos a la hora de secuestrar sesiones a través de un ataque de fuerza bruta. El fallo tiene el ID interno CSCti54048. • http://seclists.org/fulldisclosure/2010/Nov/167 http://www.cisco.com/en/US/products/products_security_response09186a0080b56d0d.html http://www.trustmatta.com/advisories/MATTA-2010-001.txt • CWE-310: Cryptographic Issues •

CVSS: 5.0EPSS: 0%CPEs: 14EXPL: 0

Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115, and 5230; Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway; Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway; and Unified Videoconferencing 3515 Multipoint Control Unit (MCU) improperly use cookies for web-interface credentials, which allows remote attackers to obtain sensitive information by reading a (1) cleartext or (2) base64-encoded cleartext cookie, aka Bug ID CSCti54052. Los sistemas Cisco Unified Videoconferencing (UVC) 3545, 5110, 5115, y 5230; Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway; Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway; y Unified Videoconferencing 3515 Multipoint Control Unit (MCU) utilizan las cookies para las credenciales del interfase web de forma inadecuada, lo que permite a atacantes remotos obtener información sensible leyendo una cookie en (1) texto claro o (2) texto claro codificado en base64, también conocido como error ID CSCti54052. • http://seclists.org/fulldisclosure/2010/Nov/167 http://www.cisco.com/en/US/products/products_security_response09186a0080b56d0d.html http://www.trustmatta.com/advisories/MATTA-2010-001.txt • CWE-310: Cryptographic Issues •

CVSS: 8.5EPSS: 0%CPEs: 14EXPL: 0

goform/websXMLAdminRequestCgi.cgi in Cisco Unified Videoconferencing (UVC) System 5110 and 5115, and possibly Unified Videoconferencing System 3545 and 5230, Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway, Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway, and Unified Videoconferencing 3515 Multipoint Control Unit (MCU), allows remote authenticated administrators to execute arbitrary commands via the username field, related to a "shell command injection vulnerability," aka Bug ID CSCti54059. goform/websXMLAdminRequestCgi.cgi en Cisco Unified Videoconferencing (UVC) System 5110 y 5115, y posiblemente Unified Videoconferencing System3545 y 5230, Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway, Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway, and Unified Videoconferencing 3515 Multipoint Control Unit (MCU), permite a administradores remotos autenticados ejecutar comandos de su elección a través del campo 'username', relacionado con vulnerabilidad de inyección de comando shell (shell command injection vulnerability), también conocido como "Bug ID CSCti54059". • http://seclists.org/fulldisclosure/2010/Nov/167 http://www.cisco.com/en/US/products/products_security_response09186a0080b56d0d.html http://www.securityfocus.com/bid/44922 http://www.securitytracker.com/id?1024753 http://www.trustmatta.com/advisories/MATTA-2010-001.txt • CWE-94: Improper Control of Generation of Code ('Code Injection') •