CVE-2011-2538: Command Injection
Published Oct 28, 2019
·Updated
Cisco Video Communications Server (VCS) before X7.0.3 contains a command injection vulnerability which allows remote, authenticated attackers to execute arbitrary commands.
Affected Software
1 affected component
Cisco TelePresence Video Communication Server<x7.0.3
Event History
Oct 28, 2019
CVE Published
via MITRE·08:19 PM
Data Sourced
via MITRE·08:19 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2011-2538?
CVE-2011-2538 is a command injection vulnerability in Cisco Video Communications Server (VCS) before X7.0.3.
2
What is the severity of CVE-2011-2538?
The severity of CVE-2011-2538 is critical with a CVSS score of 7.2.
3
How does CVE-2011-2538 affect Cisco TelePresence Video Communication Server?
CVE-2011-2538 affects Cisco TelePresence Video Communication Server versions up to and excluding X7.0.3.
4
How can authenticated attackers exploit CVE-2011-2538?
Authenticated attackers can exploit CVE-2011-2538 to execute arbitrary commands remotely.
5
Where can I find more information about CVE-2011-2538?
You can find more information about CVE-2011-2538 in the Cisco VCS Release Note X7-0-3 document.