CVE-2015-0713 (CNNVD-201505-238)

CRITICAL
中文标题:
多款Cisco TelePresence产品安全漏洞
英文标题:
The web framework in Cisco TelePresence Advanced Media Gateway Series Software before 1.1(1.40), Cis...
CVSS分数: 9.0
发布时间: 2015-05-25 00:00:00
漏洞类型: 授权问题
状态: PUBLISHED
数据质量分数: 0.30
数据版本: v3
漏洞描述
中文描述:

Cisco TelePresence Advanced Media Gateway Series Software等都是美国思科(Cisco)公司的产品。Cisco TelePresence Advanced Media Gateway Series Software是一款“网真”系统中的高清晰度(HD)媒体网关。Cisco TelePresence ISDN Gateway是一套网真ISDN视频网关解决方案。Cisco TelePresence MCU Software是MCU网真系列产品。 多款Cisco产品的Web框架中存在安全漏洞。远程攻击者可利用该漏洞以root权限执行任意命令。以下产品及版本受到影响:Cisco TelePresence Advanced Media Gateway Series Software 1.1(1.40)之前版本,Cisco TelePresence IP Gateway Series Software,Cisco TelePresence IP VCR Series Software 3.0(1.27)之前版本,Cisco TelePresence ISDN Gateway Software 2.2(1.94)之前版本,Cisco TelePresence MCU Software 4.4(3.54)之前版本和4.5(1.45)之前4.5版本,Cisco TelePresence MSE Supervisor Software 2.3(1.38)之前版本,Cisco TelePresence Serial Gateway Series Software 1.0(1.42)之前版本,Cisco TelePresence Server Software for Hardware 3.1(1.98)之前版本,Cisco TelePresence Server Software for Virtual Machine 4.1(1.79)之前版本。

英文描述:

The web framework in Cisco TelePresence Advanced Media Gateway Series Software before 1.1(1.40), Cisco TelePresence IP Gateway Series Software, Cisco TelePresence IP VCR Series Software before 3.0(1.27), Cisco TelePresence ISDN Gateway Software before 2.2(1.94), Cisco TelePresence MCU Software before 4.4(3.54) and 4.5 before 4.5(1.45), Cisco TelePresence MSE Supervisor Software before 2.3(1.38), Cisco TelePresence Serial Gateway Series Software before 1.0(1.42), Cisco TelePresence Server Software for Hardware before 3.1(1.98), and Cisco TelePresence Server Software for Virtual Machine before 4.1(1.79) allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors, aka Bug IDs CSCul55968, CSCur08993, CSCur15803, CSCur15807, CSCur15825, CSCur15832, CSCur15842, CSCur15850, and CSCur15855.

CWE类型:
CWE-264
标签:
(暂无数据)
受影响产品
厂商 产品 版本 版本范围 平台 CPE
cisco telepresence_advanced_media_gateway 1.0\(.1.13\) - - cpe:2.3:a:cisco:telepresence_advanced_media_gateway:1.0\(.1.13\):*:*:*:*:*:*:*
cisco telepresence_advanced_media_gateway 1.1\(.1.14\) - - cpe:2.3:a:cisco:telepresence_advanced_media_gateway:1.1\(.1.14\):*:*:*:*:*:*:*
cisco telepresence_advanced_media_gateway 1.1\(1.34\) - - cpe:2.3:a:cisco:telepresence_advanced_media_gateway:1.1\(1.34\):*:*:*:*:*:*:*
cisco telepresence_ip_gateway 2.0.1.7 - - cpe:2.3:a:cisco:telepresence_ip_gateway:2.0.1.7:*:*:*:*:*:*:*
cisco telepresence_ip_gateway 2.0.1.11 - - cpe:2.3:a:cisco:telepresence_ip_gateway:2.0.1.11:*:*:*:*:*:*:*
cisco telepresence_ip_gateway 2.0.3.34 - - cpe:2.3:a:cisco:telepresence_ip_gateway:2.0.3.34:*:*:*:*:*:*:*
cisco telepresence_ip_vcr_1.0_converter 1.0\(1.9\) - - cpe:2.3:a:cisco:telepresence_ip_vcr_1.0_converter:1.0\(1.9\):*:*:*:*:*:*:*
cisco telepresence_ip_vcr_2.4 1.2 - - cpe:2.3:a:cisco:telepresence_ip_vcr_2.4:1.2:*:*:*:*:*:*:*
cisco telepresence_ip_vcr_3.0 1.22 - - cpe:2.3:a:cisco:telepresence_ip_vcr_3.0:1.22:*:*:*:*:*:*:*
cisco telepresence_ip_vcr_3.0 1.24 - - cpe:2.3:a:cisco:telepresence_ip_vcr_3.0:1.24:*:*:*:*:*:*:*
cisco telepresence_isdn_gw_3241 2.0\(1.51\) - - cpe:2.3:a:cisco:telepresence_isdn_gw_3241:2.0\(1.51\):*:*:*:*:*:*:*
cisco telepresence_isdn_gw_3241 2.1\(1.22\) - - cpe:2.3:a:cisco:telepresence_isdn_gw_3241:2.1\(1.22\):*:*:*:*:*:*:*
cisco telepresence_isdn_gw_3241 2.1\(1.43\) - - cpe:2.3:a:cisco:telepresence_isdn_gw_3241:2.1\(1.43\):*:*:*:*:*:*:*
cisco telepresence_isdn_gw_3241 2.1\(1.49\) - - cpe:2.3:a:cisco:telepresence_isdn_gw_3241:2.1\(1.49\):*:*:*:*:*:*:*
cisco telepresence_isdn_gw_3241 2.1\(1.56\) - - cpe:2.3:a:cisco:telepresence_isdn_gw_3241:2.1\(1.56\):*:*:*:*:*:*:*
cisco telepresence_mcu_software 4.1\(1.51\) - - cpe:2.3:a:cisco:telepresence_mcu_software:4.1\(1.51\):*:*:*:*:*:*:*
cisco telepresence_mcu_software 4.1\(1.59\) - - cpe:2.3:a:cisco:telepresence_mcu_software:4.1\(1.59\):*:*:*:*:*:*:*
cisco telepresence_mcu_software 4.2\(1.43\) - - cpe:2.3:a:cisco:telepresence_mcu_software:4.2\(1.43\):*:*:*:*:*:*:*
cisco telepresence_mcu_software 4.2\(1.46\) - - cpe:2.3:a:cisco:telepresence_mcu_software:4.2\(1.46\):*:*:*:*:*:*:*
cisco telepresence_mcu_software 4.2\(1.50\) - - cpe:2.3:a:cisco:telepresence_mcu_software:4.2\(1.50\):*:*:*:*:*:*:*
cisco telepresence_mcu_software 4.3\(1.68\) - - cpe:2.3:a:cisco:telepresence_mcu_software:4.3\(1.68\):*:*:*:*:*:*:*
cisco telepresence_mcu_software 4.3\(2.18\) - - cpe:2.3:a:cisco:telepresence_mcu_software:4.3\(2.18\):*:*:*:*:*:*:*
cisco telepresence_mcu_software 4.3\(2.30\) - - cpe:2.3:a:cisco:telepresence_mcu_software:4.3\(2.30\):*:*:*:*:*:*:*
cisco telepresence_mcu_software 4.3\(2.32\) - - cpe:2.3:a:cisco:telepresence_mcu_software:4.3\(2.32\):*:*:*:*:*:*:*
cisco telepresence_mcu_software 4.4\(3.42\) - - cpe:2.3:a:cisco:telepresence_mcu_software:4.4\(3.42\):*:*:*:*:*:*:*
cisco telepresence_mcu_software 4.4\(3.49\) - - cpe:2.3:a:cisco:telepresence_mcu_software:4.4\(3.49\):*:*:*:*:*:*:*
cisco telepresence_serial_gateway 1.0.1.23 - - cpe:2.3:a:cisco:telepresence_serial_gateway:1.0.1.23:*:*:*:*:*:*:*
cisco telepresence_serial_gateway 1.0.1.34 - - cpe:2.3:a:cisco:telepresence_serial_gateway:1.0.1.34:*:*:*:*:*:*:*
cisco telepresence_serial_gateway 1.0.1.38 - - cpe:2.3:a:cisco:telepresence_serial_gateway:1.0.1.38:*:*:*:*:*:*:*
cisco telepresence_server_software 2.1\(1.33\) - - cpe:2.3:a:cisco:telepresence_server_software:2.1\(1.33\):*:*:*:*:*:*:*
cisco telepresence_server_software 2.1\(1.37\) - - cpe:2.3:a:cisco:telepresence_server_software:2.1\(1.37\):*:*:*:*:*:*:*
cisco telepresence_server_software 2.2\(1.43\) - - cpe:2.3:a:cisco:telepresence_server_software:2.2\(1.43\):*:*:*:*:*:*:*
cisco telepresence_server_software 2.2\(1.48\) - - cpe:2.3:a:cisco:telepresence_server_software:2.2\(1.48\):*:*:*:*:*:*:*
cisco telepresence_server_software 2.2\(1.54\) - - cpe:2.3:a:cisco:telepresence_server_software:2.2\(1.54\):*:*:*:*:*:*:*
cisco telepresence_server_software 2.3\(1.55\) - - cpe:2.3:a:cisco:telepresence_server_software:2.3\(1.55\):*:*:*:*:*:*:*
cisco telepresence_server_software 2.3\(1.57\) - - cpe:2.3:a:cisco:telepresence_server_software:2.3\(1.57\):*:*:*:*:*:*:*
cisco telepresence_server_software 3.0\(2.24\) - - cpe:2.3:a:cisco:telepresence_server_software:3.0\(2.24\):*:*:*:*:*:*:*
cisco telepresence_server_software 4.0\(1.57\) - - cpe:2.3:a:cisco:telepresence_server_software:4.0\(1.57\):*:*:*:*:*:*:*
cisco telepresence_server_software 4.0\(2.8\) - - cpe:2.3:a:cisco:telepresence_server_software:4.0\(2.8\):*:*:*:*:*:*:*
cisco telepresence_supervisor_mse_8050_software 2.1\(1.18\) - - cpe:2.3:a:cisco:telepresence_supervisor_mse_8050_software:2.1\(1.18\):*:*:*:*:*:*:*
cisco telepresence_supervisor_mse_8050_software 2.2\(1.17\) - - cpe:2.3:a:cisco:telepresence_supervisor_mse_8050_software:2.2\(1.17\):*:*:*:*:*:*:*
cisco telepresence_supervisor_mse_8050_software 2.3\(1.32\) - - cpe:2.3:a:cisco:telepresence_supervisor_mse_8050_software:2.3\(1.32\):*:*:*:*:*:*:*
解决方案
中文解决方案:
(暂无数据)
英文解决方案:
(暂无数据)
临时解决方案:
(暂无数据)
参考链接
20150513 Command Injection Vulnerability in Multiple Cisco TelePresence Products vendor-advisory
cve.org
访问
CVSS评分详情
9.0
CRITICAL
CVSS向量: AV:N/AC:L/Au:S/C:C/I:C/A:C
CVSS版本: 2.0
机密性
COMPLETE
完整性
COMPLETE
可用性
COMPLETE
时间信息
发布时间:
2015-05-25 00:00:00
修改时间:
2024-08-06 04:17:32
创建时间:
2025-11-11 15:33:58
更新时间:
2025-11-11 15:51:57
利用信息
暂无可利用代码信息
数据源详情
数据源 记录ID 版本 提取时间
CVE cve_CVE-2015-0713 2025-11-11 15:18:53 2025-11-11 07:33:58
NVD nvd_CVE-2015-0713 2025-11-11 14:54:50 2025-11-11 07:42:41
CNNVD cnnvd_CNNVD-201505-238 2025-11-11 15:09:33 2025-11-11 07:51:57
版本与语言
当前版本: v3
主要语言: EN
支持语言:
EN ZH
安全公告
暂无安全公告信息
变更历史
v3 CNNVD
2025-11-11 15:51:57
vulnerability_type: 未提取 → 授权问题; cnnvd_id: 未提取 → CNNVD-201505-238; data_sources: ['cve', 'nvd'] → ['cnnvd', 'cve', 'nvd']
查看详细变更
  • vulnerability_type: 未提取 -> 授权问题
  • cnnvd_id: 未提取 -> CNNVD-201505-238
  • data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
v2 NVD
2025-11-11 15:42:41
severity: SeverityLevel.MEDIUM → SeverityLevel.CRITICAL; cvss_score: 未提取 → 9.0; cvss_vector: NOT_EXTRACTED → AV:N/AC:L/Au:S/C:C/I:C/A:C; cvss_version: NOT_EXTRACTED → 2.0; affected_products_count: 0 → 42; data_sources: ['cve'] → ['cve', 'nvd']
查看详细变更
  • severity: SeverityLevel.MEDIUM -> SeverityLevel.CRITICAL
  • cvss_score: 未提取 -> 9.0
  • cvss_vector: NOT_EXTRACTED -> AV:N/AC:L/Au:S/C:C/I:C/A:C
  • cvss_version: NOT_EXTRACTED -> 2.0
  • affected_products_count: 0 -> 42
  • data_sources: ['cve'] -> ['cve', 'nvd']