A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to write files to the /root directory of an affected device. The vulnerability is due to improper permission assignment. An attacker could exploit this vulnerability by logging in as the remotesupport user and writing files to the /root directory of an affected device.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 04:29
Type | Values Removed | Values Added |
---|---|---|
References | () https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191016-tele-ce-filewrite - Vendor Advisory |
Information
Published : 2019-10-16 19:15
Updated : 2024-11-21 04:29
NVD link : CVE-2019-15962
Mitre link : CVE-2019-15962
CVE.ORG link : CVE-2019-15962
JSON object : View
Products Affected
cisco
- telepresence_collaboration_endpoint
- webex_room_55
- webex_room_70_dual
- webex_room_70_dual_g2
- webex_room_kit_mini
- webex_room_kit
- webex_board_55
- webex_room_70_single_g2
- webex_board_55s
- webex_board_70
- webex_board_85s
- webex_room_70_single
- webex_room_55_dual
- webex_board_70s