CVE-2019-7632

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
08/02/2019
Last modified:
08/02/2019

Description

LifeSize Team, Room, Passport, and Networker 220 devices allow Authenticated Remote OS Command Injection, as demonstrated by shell metacharacters in the support/mtusize.php mtu_size parameter. The lifesize default password for the cli account may sometimes be used for authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:lifesize:team_220_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lifesize:team_220:-:*:*:*:*:*:*:*
cpe:2.3:o:lifesize:passport_220_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lifesize:passport_220:-:*:*:*:*:*:*:*
cpe:2.3:o:lifesize:networker_220_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lifesize:networker_220:-:*:*:*:*:*:*:*
cpe:2.3:o:lifesize:room_220_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:lifesize:room_220:-:*:*:*:*:*:*:*