Support Us — Your donation helps us keep running

Goal: 1000 CNY,Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2019-16005
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cisco Webex Video Mesh Node Command Injection Vulnerability
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an authenticated, remote attacker to execute arbitrary commands on the affected system. The vulnerability is due to improper validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by logging in to the web-based management interface with administrative privileges and supplying crafted requests to the application. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux operating system with root privileges on a targeted node.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
在命令中使用的特殊元素转义处理不恰当(命令注入)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cisco Webex Video Mesh Software 注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco Webex Video Mesh是美国思科(Cisco)公司的一款软件。Cisco Webex Video Mesh可动态找到本地和云会议资源的最佳组合。当本地资源充足时,本地会议将停留在本地。当本地资源耗尽时,会议再扩展到云中。 Cisco Webex Video Mesh Software 2019.09.19.1956m之前版本中的Web管理界面存在注入漏洞,该漏洞源于该界面没有正确验证用户提交的输入。远程攻击者可通过登录到该界面并提交特制的请求利用该漏洞以root权限在底层Linux操
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
CiscoCisco Webex Video Mesh unspecified ~ n/a -
II. Public POCs for CVE-2019-16005
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2019-16005
Please Login to view more intelligence information
New Vulnerabilities
V. Comments for CVE-2019-16005

No comments yet


Leave a comment