Release date: 2011-10-20
Updated on: 2011-10-20
Affected Systems:
Cisco Show and Share 5.2 (2)
Cisco Show and Share 5.2 (1)
Cisco Show and Share 5 (2)
Unaffected system:
Cisco Show and Share 5.2 (2.1)
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2011-2584
Cisco Show and Share is a network broadcast and video sharing application that allows you to create secure video communications, optimize global video collaboration, and personalize connections between people.
Cisco Show and Share does not properly verify certain administrator page creden。. Malicious users can bypass certain security restrictions by accessing Encoders and Pull distributions, Push deployments, Video Encoding Formats, and Transcoding pages.
<* Source: Cisco
Link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111019-sns
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cisco
-----
Cisco has released a Security Bulletin (cisco-sa-20111019-sns) and patches for this:
Cisco-sa-20111019-sns: Cisco Show and Share Security Vulnerabilities
Link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111019-sns