Cisco Unified Videoconferencing (UVC) System 5110 and 5115, when the Linux operating system is used, uses world-readable permissions for the /etc/shadow file, which allows local users to discover encrypted passwords by reading this file, aka Bug ID CSCti54043.
2010-11-22T20:00:04.260
2025-04-11T00:51:21.963
Deferred
CVSSv2: 4.9 (MEDIUM)
AV:L/AC:L/Au:N/C:C/I:N/A:N
3.9
6.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cisco | unified_videoconferencing_system_5110_firmware | 7.0.1.13.3 | Yes |
Application | cisco | unified_videoconferencing_system_5115_firmware | 7.0.1.13.3 | Yes |
Hardware | cisco | unified_videoconferencing_system_5110 | * | Yes |
Hardware | cisco | unified_videoconferencing_system_5115 | * | Yes |
Operating System | linux | linux_kernel | * | No |