VulnerAlert



APPS
CISCO
CLOUD
PRODUCTS
04-06-2025 13:02
Tags
#injection
#product
#nifi
#exploit
#admin
#add
#products
#cloud
#cisco
#apps
#vulnerability
#affected
#arbitrary
#root
#inject
#execute
#affect
Descripción
Cisco Unified Communications Products Command Injection Vulnerability A vulnerability in the CLI of multiple Cisco products could allow an authenticated, local attacker to execute arbitrary commands on underlying operating system affected device as <em>root</em> user.<br><br> This is due improper validation user-supplied command arguments. An exploit this by executing crafted device. A successful user. To vulnerability, must have valid administrative credentials.<br><br> Cisco has released software updates that address vulnerability. There are no workarounds vulnerability.<br><br> This advisory available at following link:<br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vos-command-inject-65s2UCYy">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vos-command-inject-65s2UCYy</a><br><br> <br/>Security Impact Rating: Medium <br/>CVE: CVE-2025-20278 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vos-command-inject-65s2UCYy CISCO
CVE-2025-20278
Link externo
Ver detalles

Fuente
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vos-command-inject-65s2UCYy
Resultados similares
Coincidentes en almenos en 50% de los tags
05-06-2025 CVE-2024-3729
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to improper missing encrypt...
Ver información
05-06-2025 CVE-2025-5630
A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. This vul...
Ver información
Icons made by Freepik from www.flaticon.com
Este Proyecto fue cofinanciado por el Consejo Nacional de Ciencia y Tecnología (CONACYT) a través del PROINNOVA 2021/2023
Proyecto realizado por