CVE-2019-12622
published 2019-08-21CVE-2019-12622: A vulnerability in Cisco RoomOS Software could allow an authenticated, local attacker to write files to the underlying filesystem with root privileges. The…
PriorityP427medium5.5CVSS 3.1
AVLACLPRLUINSUCNIHAN
EPSS
0.26%
17.7th percentile
A vulnerability in Cisco RoomOS Software could allow an authenticated, local attacker to write files to the underlying filesystem with root privileges. The vulnerability is due to insufficient permission restrictions on a specific process. An attacker could exploit this vulnerability by logging in to an affected device with remote support credentials and initiating the specific process on the device and sending crafted data to that process. A successful exploit could allow the attacker to write files to the underlying file system with root privileges.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_telepresence_ce_software | >= unspecified < ce-9.7.3 | ce-9.7.3 |
| cisco | roomos | < 9.8.0 | 9.8.0 |
| cisco | roomos | <= 9.7.2 | — |
| cisco | roomos | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv3.04.1MEDIUMCVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco4.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cw6x-mqv8-rmmr: A vulnerability in Cisco RoomOS Software could allow an authenticated, local attacker to write files to the underlying filesystem with root privileges
ghsa_unreviewed·2022-05-24
CVE-2019-12622 [MEDIUM] GHSA-cw6x-mqv8-rmmr: A vulnerability in Cisco RoomOS Software could allow an authenticated, local attacker to write files to the underlying filesystem with root privileges
A vulnerability in Cisco RoomOS Software could allow an authenticated, local attacker to write files to the underlying filesystem with root privileges. The vulnerability is due to insufficient permission restrictions on a specific process. An attacker could exploit this vulnerability by logging in to an affected device with remote support credentials and initiating the specific process on the device and sending crafted data to that process. A successful exploit could allow the attacker to write files to the underlying file system with root privileges.
Cisco
Cisco RoomOS Software Privilege Escalation Vulnerability
vendor_cisco·2019-08-21·CVSS 4.1
CVE-2019-12622 [MEDIUM] CWE-275 Cisco RoomOS Software Privilege Escalation Vulnerability
Cisco RoomOS Software Privilege Escalation Vulnerability
A vulnerability in Cisco RoomOS Software could allow an authenticated, local attacker to write files to the underlying filesystem with root privileges.
The vulnerability is due to insufficient permission restrictions on a specific process. An attacker could exploit this vulnerability by logging in to an affected device with remote support credentials and initiating the specific process on the device and sending crafted data to that process. A successful exploit could allow the attacker to write files to the underlying file system with root privileges.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https:/
Cisco
Cisco RoomOS Software Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-12622 Cisco RoomOS Software Privilege Escalation Vulnerability
CVE-2019-12622: Cisco RoomOS Software Privilege Escalation Vulnerability
A vulnerability in Cisco RoomOS Software could allow an authenticated, local attacker to write files to the underlying filesystem with root privileges. The vulnerability is due to insufficient permission restrictions on a specific process. An attacker could exploit this vulnerability by logging in to an affected device with remote support credentials and initiating the specific process on the device and sending crafted data to that process. A successful exploit could allow the attacker to write files to the underlying file system with root privileges. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-275, CWE-275
Bug IDs: CSCvp79711
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-08-21
Published