Improper Verification of Cryptographic Signature in Cisco Expressway and Cisco TelePresence Video Communication Server - CVE-2021-34715
Published: August 23, 2021
Vulnerability identifier: #VU56028
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-34715
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to compromise the target system.
The vulnerability exists due to insufficient validation of the content of upgrade packages. A remote administrator can upload a malicious archive to the Upgrade page and execute arbitrary code on the target system.
Affected software
Cisco Expressway
Cisco TelePresence Video Communication Server
Cisco TelePresence Video Communication Server
How to mitigate CVE-2021-34715
Install updates from vendor's website.
Cisco Expressway - update to X14.0.3
Cisco TelePresence Video Communication Server - update to X14.0.3
Cisco TelePresence Video Communication Server - update to X14.0.3