CVE-2019-15595: Command Injection
Published Nov 25, 2019
·Updated
A privilege escalation exists in UniFi Video Controller =<3.10.6 that would allow an attacker on the local machine to run arbitrary commands.
Affected Software
2 affected components
UI Unifi Video Controller<=3.10.6
UI Unifi Video Controller
Event History
Nov 25, 2019
CVE Published
via MITRE·11:19 PM
Data Sourced
via MITRE·11:19 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-15595?
CVE-2019-15595 is considered a high-severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2019-15595?
To fix CVE-2019-15595, update the UniFi Video Controller to a version higher than 3.10.6.
3
Who is affected by CVE-2019-15595?
Users running UniFi Video Controller versions 3.10.6 and below are affected by CVE-2019-15595.
4
What is the nature of the vulnerability CVE-2019-15595?
CVE-2019-15595 is a privilege escalation vulnerability that allows an attacker on the local machine to execute arbitrary commands.
5
Can CVE-2019-15595 be exploited remotely?
CVE-2019-15595 requires local access to the machine to be exploited, thus it cannot be exploited remotely.