The image-upgrade functionality on Cisco 9900 Unified IP phones allows local users to gain privileges by placing shell commands in an unspecified parameter, aka Bug ID CSCuh10334.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-5533 | vendor advisory |
http://www.securityfocus.com/bid/62943 | vdb entry third party advisory |
http://osvdb.org/98337 | vdb entry |