First published: Wed Oct 16 2019(Updated: )
A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to execute code with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by authenticating as the remote support user and sending malicious traffic to a listener who is internal to the device. A successful exploit could allow the attacker to execute commands with root privileges.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco TelePresence Collaboration Endpoint | <9.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-15277.
CVE-2019-15277 has a severity rating of 6.7 (high).
This vulnerability occurs due to insufficient input validation in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software.
An authenticated, local attacker can exploit this vulnerability.
An attacker can exploit CVE-2019-15277 by authenticating as the re and executing code with root privileges.