Skip to main content

Cisco Products Multiple Vulnerabilities

Last Update Date: 3 Nov 2016 11:19 Release Date: 3 Nov 2016 3096 Views

RISK: Medium Risk

TYPE: Security software and application - Security Software & Appliance

TYPE: Security Software & Appliance

Multiple vulnerabilities were identified in multiple Cisco products.

A remote user can cause the target system to remotely execute code in Cisco Cisco ASR 900 Series Aggregation Services Routers.

A remote user can cause the target system to execute arbitrary code in Cisco Meeting Server.

A local user can cause the target system to execute a local shell command injection in Cisco TelePresence Endpoints.

 


Impact

  • Remote Code Execution

System / Technologies affected

  • Cisco ASR 900 Series Aggregation Services Routers: versions 3.17.0S, 3.17.1S, 3.17.2S, 3.18.0S, 3.18.1S
  • Cisco Meeting Server: versions 2.0.0 and prior
  • TelePresence Endpoints running CE or TC software

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Cisco ASR 900 Series Aggregation Services Routers: Update to 3.17.3S (scheduled for 30th November) or 3.18.2S
  • Cisco Meeting Server: Update to 2.01 or later
  • TelePresence Endpoints: No patch is currently available

 


Vulnerability Identifier


Source


Related Link