CVE-2019-1861: Cisco Industrial Network Director Remote Code Execution Vulnerability
A vulnerability in the software update feature of Cisco Industrial Network Director could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is due to improper validation of files uploaded to the affected application. An attacker could exploit this vulnerability by authenticating to the affected system using administrator privileges and uploading an arbitrary file. A successful exploit could allow the attacker to execute arbitrary code with elevated privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-1861?
CVE-2019-1861 is a vulnerability in the software update feature of Cisco Industrial Network Director.
How does CVE-2019-1861 affect Cisco Industrial Network Director?
CVE-2019-1861 allows an authenticated, remote attacker to execute arbitrary code in Cisco Industrial Network Director.
What is the severity of CVE-2019-1861?
CVE-2019-1861 has a severity rating of 7.2 (Critical).
How can an attacker exploit CVE-2019-1861?
An attacker can exploit CVE-2019-1861 by uploading malicious files to the affected application.
What is the fix for CVE-2019-1861?
To fix CVE-2019-1861, users should upgrade to a version of Cisco Industrial Network Director that is newer than 1.6.0.