CVE-2010-4303

Cisco Unified Videoconferencing System 5110 and 5115 - Unprotected Credential Disclosure via World-Readable /etc/shadow

Title source: llm
STIX 2.1

Description

Cisco Unified Videoconferencing (UVC) System 5110 and 5115, when the Linux operating system is used, uses world-readable permissions for the /etc/shadow file, which allows local users to discover encrypted passwords by reading this file, aka Bug ID CSCti54043.

References (3)

Core 3
Core References
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2010/Nov/167

Scores

EPSS 0.0035
EPSS Percentile 27.8%

Details

CWE
CWE-255
Status published
Products (4)
cisco/unified_videoconferencing_system_5110
cisco/unified_videoconferencing_system_5110_firmware 7.0.1.13.3
cisco/unified_videoconferencing_system_5115
cisco/unified_videoconferencing_system_5115_firmware 7.0.1.13.3
Published Nov 22, 2010
Tracked Since Feb 18, 2026