LifeSize records
5 published records for vendor lifesize.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 20%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-20 Improper Input Validation1
- CWE-287 Improper Authentication1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2011-2763Weaponized | The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) and 4.7.18 allows remote attackers to execute arbitrary commands via a molifesize · lifesize room appliance · CWE-20 | High7.5 | — | 36.1% | Sep 2, 2011 |
37Monitor | CVE-2019-7632No exploit | LifeSize Team, Room, Passport, and Networker 220 devices allow Authenticated Remote OS Command Injection, as demonstrated by shell metacharalifesize · team 220 firmware · CWE-78 | High8.8 | — | 6.5% | Feb 8, 2019 |
37Monitor | CVE-2019-3702No exploit | A Remote Code Execution issue in the DNS Query Web UI in Lifesize Icon LS_RM3_3.7.0 (2421) allows remote authenticated attackers to execute lifesize · icon 300 firmware · CWE-78 | High8.8 | — | 5.2% | May 13, 2019 |
24Monitor | CVE-2018-17981No exploit | Lifesize Express ls ex2_4.7.10 2000 (14) devices allow XSS via the interface/interface.php brand parameter.lifesize · express 220 firmware · CWE-79 | Medium6.1 | — | 0.8% | Jan 21, 2020 |
21Monitor | CVE-2011-2762No exploit | The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) allows remote attackers to bypass authentication via unspecified data asslifesize · lifesize room appliance software · CWE-287 | Medium5.0 | — | 2.3% | Sep 2, 2011 |
- CVE-2011-276341Plan
The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) and 4.7.18 allows remote attackers to execute arbitrary commands via a mo
HighCVSS 7.5WeaponizedEPSS 36%lifesize · lifesize room applianceSep 2, 2011
- CVE-2019-763237Monitor
LifeSize Team, Room, Passport, and Networker 220 devices allow Authenticated Remote OS Command Injection, as demonstrated by shell metachara
HighCVSS 8.8No exploitEPSS 6%lifesize · team 220 firmwareFeb 8, 2019
- CVE-2019-370237Monitor
A Remote Code Execution issue in the DNS Query Web UI in Lifesize Icon LS_RM3_3.7.0 (2421) allows remote authenticated attackers to execute
HighCVSS 8.8No exploitEPSS 5%lifesize · icon 300 firmwareMay 13, 2019
- CVE-2018-1798124Monitor
Lifesize Express ls ex2_4.7.10 2000 (14) devices allow XSS via the interface/interface.php brand parameter.
MediumCVSS 6.1No exploitEPSS 1%lifesize · express 220 firmwareJan 21, 2020
- CVE-2011-276221Monitor
The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) allows remote attackers to bypass authentication via unspecified data ass
MediumCVSS 5.0No exploitEPSS 2%lifesize · lifesize room appliance softwareSep 2, 2011