ZeroHour

CVE-2019-7632

PoC
CVSS 3.0
8.8 high
EPSS
6%p93
Published
()
Modified
Description

LifeSize Team, Room, Passport, and Networker 220 devices allow Authenticated Remote OS Command Injection, as demonstrated by shell metacharacters in the support/mtusize.php mtu_size parameter. The lifesize default password for the cli account may sometimes be used for authentication.

Vendors
lifesize
Products
team 220 firmware, passport 220 firmware, networker 220 firmware, room 220 firmware
Weakness
CWE-78
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.