Remote OS Command Injection Vulnerability in LifeSize Video Conferencing Equipment
CVE-2019-7632

8.8HIGH

Key Information:

Vendor

Lifesize

Vendor
CVE Published:
8 February 2019

What is CVE-2019-7632?

LifeSize Team, Room, Passport, and Networker 220 devices are susceptible to an authenticated remote OS command injection vulnerability. This flaw exists due to improper handling of the mtu_size parameter in the support/mtusize.php script. Attackers with valid credentials may exploit this weakness by inserting shell metacharacters, potentially allowing unauthorized execution of commands on the affected devices. Notably, the use of default passwords for the CLI account may further expose these devices to attacks.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.