Guest

Preview Tool

Cisco Bug: CSCur04550 - Bash Code Injection Vulnerability (CVE-2014-6271/CVE-2014-7169)

Last Modified

Sep 17, 2019

Products (15)

  • Cisco TelePresence MCU 4500 Series
  • Cisco TelePresence MCU 4520
  • Cisco TelePresence MCU 4505
  • Cisco TelePresence MCU 4510
  • Cisco TelePresence MCU 5320
  • Cisco TelePresence MCU 4205
  • Cisco TelePresence MCU 4215
  • Cisco TelePresence MCU 4220
  • Cisco TelePresence MCU MSE 8420
  • Cisco TelePresence MCU 4203
View all products in Bug Search Tool Login Required

Known Affected Releases

4.4(3.67)

Description (partial)

Symptom:
The following Cisco products:

Cisco TelePresence MCU 4200 Series
Cisco TelePresence MCU 4500 Series
Cisco TelePresence MCU MSE 8420
Cisco TelePresence MCU MSE 8510
Cisco TelePresence MCU 5300 Series

include a version of Bash that may be affected by the vulnerabilities identified by the following Common Vulnerability and Exposures (CVE) IDs:

CVE-2014-6271 
CVE-2014-6277
CVE-2014-6278
CVE-2014-7169
CVE-2014-7186
CVE-2014-7187

Cisco has analyzed this vulnerability and concluded that the previously listed products are not impacted. Whilst some earlier versions of the listed products contain a copy of the Bash binary, this is not used by the operating system or any network facing service.

Conditions:
MCU 4.5(1.45) is the first release to have the Bash binary completely removed.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.