Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.105351
Kategorie:CISCO
Titel:Cisco TelePresence Integrator C Series Authentication Bypass Vulnerability (CSCuv00604)
Zusammenfassung:Cisco TelePresence Integrator C Series devices running TC; Software are prone to an authentication-bypass vulnerability because it fails to sufficiently; sanitize the user-supplied input.
Beschreibung:Summary:
Cisco TelePresence Integrator C Series devices running TC
Software are prone to an authentication-bypass vulnerability because it fails to sufficiently
sanitize the user-supplied input.

Vulnerability Insight:
A vulnerability in Cisco TelePresence Integrator C Series could
allow an unauthenticated, remote attacker to bypass authentication.

The vulnerability is due to insufficient validation of user-supplied values. An attacker could
exploit this vulnerability by sending multiple request parameters to an affected device.

This issue is tracked by Cisco Bug ID CSCuv00604

Vulnerability Impact:
An attacker can exploit this issue to bypass the authentication
mechanism on an affected device. This may lead to further attacks.

Affected Software/OS:
Cisco TelePresence Integrator C Series devices running TC
Software prior to versions 7.3.4.

Solution:
Update to version 7.3.4 or later.

CVSS Score:
6.4

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2015-4271
Cisco Security Advisory: 20150714 Cisco TelePresence Integrator C Series Multiple Request Parameter Vulnerability
http://tools.cisco.com/security/center/viewAlert.x?alertId=39880
http://www.securitytracker.com/id/1032931
CopyrightCopyright (C) 2015 Greenbone AG

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.