Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-1911


A vulnerability in the CLI of Cisco Unified Communications Domain Manager (Cisco Unified CDM) Software could allow an authenticated, local attacker to escape the restricted shell. The vulnerability is due to insufficient input validation of shell commands. An attacker could exploit this vulnerability by executing crafted commands in the shell. A successful exploit could allow the attacker to escape the restricted shell and access commands in the context of the restricted shell user, which does not have root privileges.


Published

2019-07-06T02:15:11.620

Last Modified

2024-11-21T04:37:40.217

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 5.3 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-216
  • Type: Primary
    CWE-216

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco hosted_collaboration_solution ≤ 11.5\(3\)pb3 Yes

References