CVE-2010-3037
highCVSS v3 Base Score
8.5
AV:N/AC:M/Au:S/C:C/I:C/A:C
EPSS Score
2.3%
Exploitation probability in 30 days
Top 15% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
M
Confidentiality
C
Integrity
C
Availability
C
Published: November 22, 2010 (5651 days ago)
Last Modified: April 29, 2026
Vendor: Cisco
Source: NVD
Vulnerability Report
Generated by CyberWatcher
Description
goform/websXMLAdminRequestCgi.cgi in Cisco Unified Videoconferencing (UVC) System 5110 and 5115, and possibly Unified Videoconferencing System 3545 and 5230, Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway, Unified Videoconferencing 3522 Basic Rate Interfaces (BRI) Gateway, and Unified Videoconferencing 3515 Multipoint Control Unit (MCU), allows remote authenticated administrators to execute arbitrary commands via the username field, related to a "shell command injection vulnerability," aka Bug ID CSCti54059.
CWE
CWE-94Affected Products
cisco unified videoconferencing system 5110 firmwarecisco unified videoconferencing system 5115 firmwarecisco unified videoconferencing system 5110cisco unified videoconferencing system 5115cisco unified videoconferencing system 3515 multipoint control unit firmwarecisco unified videoconferencing system 3522 basic rate interface gateway firmwarecisco unified videoconferencing system 3527 primary rate interface gateway firmwarecisco unified videoconferencing system 3545 firmwarecisco unified videoconferencing system 5230 firmwarecisco unified videoconferencing system 3515 multipoint control unit