Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-15962


A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to write files to the /root directory of an affected device. The vulnerability is due to improper permission assignment. An attacker could exploit this vulnerability by logging in as the remotesupport user and writing files to the /root directory of an affected device.


Published

2019-10-16T19:15:15.660

Last Modified

2024-11-21T04:29:49.890

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.4 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:N/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

9.2

Weaknesses
  • Type: Secondary
    CWE-275
  • Type: Primary
    CWE-276

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco telepresence_collaboration_endpoint 7.3.18 Yes
Application cisco telepresence_collaboration_endpoint 8.3.7 Yes
Application cisco telepresence_collaboration_endpoint 9.6.4 Yes
Application cisco telepresence_collaboration_endpoint 9.7.2 Yes
Application cisco telepresence_collaboration_endpoint 9.8.0 Yes
Hardware cisco webex_board_55 - No
Hardware cisco webex_board_55s - No
Hardware cisco webex_board_70 - No
Hardware cisco webex_board_70s - No
Hardware cisco webex_board_85s - No
Hardware cisco webex_room_55 - No
Hardware cisco webex_room_55_dual - No
Hardware cisco webex_room_70_dual - No
Hardware cisco webex_room_70_dual_g2 - No
Hardware cisco webex_room_70_single - No
Hardware cisco webex_room_70_single_g2 - No
Hardware cisco webex_room_kit - No
Hardware cisco webex_room_kit_mini - No

References