Executive Summary
| Summary | |
|---|---|
| Title | Multiple Vulnerabilities in Cisco Unified Videoconferencing Products |
| Informations | |||
|---|---|---|---|
| Name | cisco-sa-20101206-cuvc | First vendor Publication | 2010-12-02 |
| Vendor | Cisco | Last vendor Modification | 2010-12-06 |
| Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
|---|---|---|---|
| Cvss Base Score | 10 | Attack Range | Network |
| Cvss Impact Score | 10 | Attack Complexity | Low |
| Cvss Expoit Score | 10 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
This is the Cisco Product Security Incident Response Team (PSIRT) security advisory related to a posting entitled "Cisco Unified Videoconferencing multiple vulnerabilities" by Florent Daigniere of Matta Consulting regarding vulnerabilities in the Cisco Unified Videoconferencing (Cisco UVC) 5100 series products. Several of the vulnerabilities also impact Cisco Unified Videoconferencing 5200 and 3500 Series Products. |
Original Source
| Url : http://www.cisco.com/en/US/products/products_security_advisory09186a0080b5 (...) |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-255 | Credentials Management |
| CWE-94 | Failure to Control Generation of Code ('Code Injection') |
CPE : Common Platform Enumeration
| Type | Description | Count |
|---|---|---|
| Application | 1 | |
| Application | 1 | |
| Application | 1 | |
| Application | 1 | |
| Application | 1 | |
| Application | 1 | |
| Application | 1 | |
| Hardware | 1 | |
| Hardware | 1 | |
| Hardware | 1 | |
| Hardware | 1 | |
| Hardware | 1 | |
| Hardware | 1 | |
| Hardware | 1 |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 69447 | Cisco Unified Videoconferencing (UVC) Multiple Products Multiple Account Defa... |
| 69446 | Cisco Unified Videoconferencing (UVC) Multiple Products goform/websXMLAdminRe... |

cisco-sa-20101206-cuvc
(Critical)
(High)





