CVE-2021-34715 is a high-severity vulnerability affecting Cisco Expressway Series and Cisco TelePresence Video Communication Server, allowing an authenticated, remote attacker to execute code with user-level privileges on the underlying operating system. The vulnerability stems from insufficient validation of upgrade package content, enabling an attacker to upload a malicious archive via the administrative web interface. With a CVSS score of 7.2, a successful exploit could lead to full compromise of the affected system. While no public exploit code or active exploitation has been observed, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= x8.8.0CPE matchmatch criteria | cpe:2.3:a:cisco:expressway:*:*:*:*:*:*:*:* | ||
<= x8.8CPE matchmatch criteria | cpe:2.3:a:cisco:telepresence_video_communication_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.