CVE-2021-34715

MEDIUM

Cisco Expressway and TelePresence VCS - Authenticated Remote Code Execution via Upgrade Package

Title source: llm
STIX 2.1

Description

A vulnerability in the image verification function of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with internal user privileges on the underlying operating system. The vulnerability is due to insufficient validation of the content of upgrade packages. An attacker could exploit this vulnerability by uploading a malicious archive to the Upgrade page of the administrative web interface. A successful exploit could allow the attacker to execute code with user-level privileges (the _nobody account) on the underlying operating system.

References (1)

Core 1
Core References

Scores

CVSS v3 4.7
EPSS 0.0067
EPSS Percentile 71.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-347
Status published
Products (2)
cisco/expressway < x8.8.0
cisco/telepresence_video_communication_server < x8.8
Published Aug 18, 2021
Tracked Since Feb 18, 2026