CVE-2021-34716
Cisco Expressway Series and TelePresence Video Communication Server Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as the root user. This vulnerability is due to incorrect handling of certain crafted software images that are uploaded to the affected device. An attacker could exploit this vulnerability by authenticating to the system as an administrative user and then uploading specific crafted software images to the affected device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system as the root user.
Una vulnerabilidad en la interfaz de administración basada en la web de la serie Expressway de Cisco y Cisco TelePresence Video Communication Server (VCS), podría permitir a un atacante autenticado remoto ejecutar código arbitrario en el sistema operativo subyacente como usuario root. Esta vulnerabilidad es debido al manejo incorrecto de determinadas imágenes de software diseñadas que son cargados en el dispositivo afectado. Un atacante podría explotar esta vulnerabilidad al autenticarse en el sistema como un usuario administrativo y luego cargando imágenes de software específicamente diseñadas en el dispositivo afectado. Una explotación con éxito podría permitir al atacante ejecutar código arbitrario en el sistema operativo subyacente como usuario root.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2021-06-15 CVE Reserved
- 2021-08-18 CVE Published
- 2023-11-10 EPSS Updated
- 2024-11-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-460: Improper Cleanup on Thrown Exception
- CWE-755: Improper Handling of Exceptional Conditions
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ewrce-QPynNCjh | 2023-11-07 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Expressway Search vendor "Cisco" for product "Expressway" | >= x8.6.0 < x14.1 Search vendor "Cisco" for product "Expressway" and version " >= x8.6.0 < x14.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Telepresence Video Communication Server Search vendor "Cisco" for product "Telepresence Video Communication Server" | >= x8.6 <= x14.0.3 Search vendor "Cisco" for product "Telepresence Video Communication Server" and version " >= x8.6 <= x14.0.3" | - |
Affected
|