CVE-2019-15273: Cisco TelePresence Collaboration Endpoint Software Arbitrary File Overwrite Vulnerabilities
Multiple vulnerabilities in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to overwrite arbitrary files. The vulnerabilities are due to insufficient permission enforcement. An attacker could exploit these vulnerabilities by authenticating as the remote support user and submitting malicious input to specific commands. A successful exploit could allow the attacker to overwrite arbitrary files on the underlying filesystem. The attacker has no control over the contents of the data written to the file. Overwriting a critical file could cause the device to crash, resulting in a denial of service condition (DoS).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-15273?
CVE-2019-15273 is a vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software that could allow an authenticated, local attacker to overwrite arbitrary files.
How severe is CVE-2019-15273?
CVE-2019-15273 has a severity rating of medium with a CVSS score of 4.4 (out of 10).
How does CVE-2019-15273 affect Cisco TelePresence Collaboration Endpoint Software?
CVE-2019-15273 affects Cisco TelePresence Collaboration Endpoint Software versions up to and including 9.8.1.
How can an attacker exploit CVE-2019-15273?
An attacker can exploit CVE-2019-15273 by authenticating to the CLI and using insufficient permission enforcement to overwrite arbitrary files.
How can I fix CVE-2019-15273?
To fix CVE-2019-15273, Cisco recommends upgrading to a fixed software release.