CVE-2016-1468: OS Command Injection
The administrative web interface in Cisco TelePresence Video Communication Server Expressway X8.5.2 allows remote authenticated users to execute arbitrary commands via crafted fields, aka Bug ID CSCuv12531.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1468?
CVE-2016-1468 is classified as a high-severity vulnerability that allows remote authenticated users to execute arbitrary commands.
How do I fix CVE-2016-1468?
To remediate CVE-2016-1468, upgrade the Cisco TelePresence Video Communication Server Expressway to a version that is not affected by this vulnerability.
Who is affected by CVE-2016-1468?
CVE-2016-1468 impacts users of Cisco TelePresence Video Communication Server Expressway version X8.5.2.
What type of vulnerability is CVE-2016-1468?
CVE-2016-1468 is a command injection vulnerability in the administrative web interface.
Can CVE-2016-1468 be exploited remotely?
Yes, CVE-2016-1468 can be exploited by remote authenticated users to execute arbitrary commands.