CVE-2010-3039
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
09/11/2010
Last modified:
11/04/2025
Description
/usr/local/cm/bin/pktCap_protectData in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6, 7, and 8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in a request to the administrative interface, aka Bug IDs CSCti52041 and CSCti74930.
Impact
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:cisco:unified_communications_manager:6.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:unified_communications_manager:6.1\(1\):*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:unified_communications_manager:6.1\(1a\):*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:unified_communications_manager:6.1\(1b\):*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:unified_communications_manager:6.1\(2\):*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:unified_communications_manager:6.1\(2\)su1:*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:unified_communications_manager:6.1\(2\)su1a:*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:unified_communications_manager:6.1\(3\):*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:unified_communications_manager:6.1\(3a\):*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:unified_communications_manager:6.1\(3b\):*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:unified_communications_manager:6.1\(3b\)su1:*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:unified_communications_manager:6.1\(4\):*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:unified_communications_manager:6.1\(4\)su1:*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:unified_communications_manager:6.1\(4a\):*:*:*:*:*:*:* | ||
cpe:2.3:a:cisco:unified_communications_manager:6.1\(4a\)su2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://seclists.org/fulldisclosure/2010/Nov/40
- http://secunia.com/advisories/42129
- http://tools.cisco.com/security/center/viewAlert.x?alertId=21656
- http://www.nsense.fi/advisories/nsense_2010_003.txt
- http://www.securityfocus.com/archive/1/514668/100/0/threaded
- http://www.securityfocus.com/bid/44672
- http://www.securitytracker.com/id?1024694=
- http://www.vupen.com/english/advisories/2010/2915
- http://seclists.org/fulldisclosure/2010/Nov/40
- http://secunia.com/advisories/42129
- http://tools.cisco.com/security/center/viewAlert.x?alertId=21656
- http://www.nsense.fi/advisories/nsense_2010_003.txt
- http://www.securityfocus.com/archive/1/514668/100/0/threaded
- http://www.securityfocus.com/bid/44672
- http://www.securitytracker.com/id?1024694=
- http://www.vupen.com/english/advisories/2010/2915