CVE-2010-4303
Cisco Unified Videoconferencing System 5110 and 5115 - Unprotected Credential Disclosure via World-Readable /etc/shadow
Title source: llmDescription
Cisco Unified Videoconferencing (UVC) System 5110 and 5115, when the Linux operating system is used, uses world-readable permissions for the /etc/shadow file, which allows local users to discover encrypted passwords by reading this file, aka Bug ID CSCti54043.
References (3)
Core 3
Core References
Various Sources x_refsource_misc
http://www.trustmatta.com/advisories/MATTA-2010-001.txt
Vendor Advisory vendor-advisory
x_refsource_cisco
http://www.cisco.com/en/US/products/products_security_response09186a0080b56d0d.html
Mailing List mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2010/Nov/167
Scores
EPSS
0.0035
EPSS Percentile
27.8%
Details
CWE
CWE-255
Status
published
Products (4)
cisco/unified_videoconferencing_system_5110
cisco/unified_videoconferencing_system_5110_firmware
7.0.1.13.3
cisco/unified_videoconferencing_system_5115
cisco/unified_videoconferencing_system_5115_firmware
7.0.1.13.3
Published
Nov 22, 2010
Tracked Since
Feb 18, 2026