VYPR
Unrated severityNVD Advisory· Published Oct 20, 2011· Updated Apr 29, 2026

CVE-2011-2585

CVE-2011-2585

Description

Cisco Show and Share 5.2(2) and earlier allow authenticated users with video upload privileges to upload and execute arbitrary code.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cisco Show and Share 5.2(2) and earlier allow authenticated users with video upload privileges to upload and execute arbitrary code.

Vulnerability

Cisco Show and Share versions 5(2), 5.2(1), and 5.2(2) before 5.2(2.1) contain a vulnerability that allows remote authenticated users to upload and execute arbitrary code. The issue is identified as Bug ID CSCto69857 and is described in Cisco Security Advisory cisco-sa-20111019-sns [1]. The vulnerability exists in the video upload functionality, which does not properly validate uploaded files, enabling arbitrary code execution.

Exploitation

An attacker must have valid credentials for the Cisco Show and Share application and must possess video upload privileges. With these privileges, the attacker can upload a crafted file containing malicious code, which is then executed on the server. No user interaction beyond the attacker's own actions is required, and the attacker can perform this remotely over the network [1].

Impact

Successful exploitation allows the attacker to execute arbitrary code on the underlying server. This can lead to complete compromise of the application and the host system, including unauthorized access to data, modification of content, and potential denial of service. The privilege level achieved is that of the application process, which typically runs with high privileges [1].

Mitigation

Cisco has released fixed version 5.2(2.1) to address this vulnerability. Users are advised to upgrade to this version or later. The advisory also notes that version 5.2(3) does not support certain MCS Server Appliances, so administrators should use 5.2(2.1) or later as recommended. No workarounds are provided in the reference [1].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4
  • cpe:2.3:a:cisco:show_and_share:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:cisco:show_and_share:*:*:*:*:*:*:*:*range: <=5.2\(2\)
    • cpe:2.3:a:cisco:show_and_share:5\(2\):*:*:*:*:*:*:*
    • cpe:2.3:a:cisco:show_and_share:5.2\(1\):*:*:*:*:*:*:*
    • (no CPE)range: <5.2(2.1)

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.