Cisco Products Multiple Vulnerabilities
RISK: Medium Risk
TYPE: Security software and application - Security Software & Appliance
Multiple vulnerabilities were identified in multiple Cisco products.
A remote user can cause the target system to remotely execute code in Cisco Cisco ASR 900 Series Aggregation Services Routers.
A remote user can cause the target system to execute arbitrary code in Cisco Meeting Server.
A local user can cause the target system to execute a local shell command injection in Cisco TelePresence Endpoints.
Impact
- Remote Code Execution
System / Technologies affected
- Cisco ASR 900 Series Aggregation Services Routers: versions 3.17.0S, 3.17.1S, 3.17.2S, 3.18.0S, 3.18.1S
- Cisco Meeting Server: versions 2.0.0 and prior
- TelePresence Endpoints running CE or TC software
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Cisco ASR 900 Series Aggregation Services Routers: Update to 3.17.3S (scheduled for 30th November) or 3.18.2S
- Cisco Meeting Server: Update to 2.01 or later
- TelePresence Endpoints: No patch is currently available
Vulnerability Identifier
Source
Related Link
Share with