CVE-2019-12672
published 2019-09-25CVE-2019-12672: A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker with physical access to an affected device to execute…
PriorityP432medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
EPSS
0.60%
44.9th percentile
A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker with physical access to an affected device to execute arbitrary code on the underlying operating system (OS) with root privileges. The vulnerability is due to insufficient file location validation. An attacker could exploit this vulnerability by placing code in a specific format on a USB device and inserting it into an affected Cisco device. A successful exploit could allow the attacker to execute the code with root privileges on the underlying OS of the affected device.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios_xe_software_3.11.1s | >= unspecified < n/a | n/a |
| cisco | ios | — | — |
| cisco | ios_xe | — | — |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.06.2MEDIUMCVSS:3.0/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-chch-v8xx-wcp7: A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker with physical access to an affected device to
ghsa_unreviewed·2022-05-24
CVE-2019-12672 [HIGH] CWE-59 GHSA-chch-v8xx-wcp7: A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker with physical access to an affected device to
A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker with physical access to an affected device to execute arbitrary code on the underlying operating system (OS) with root privileges. The vulnerability is due to insufficient file location validation. An attacker could exploit this vulnerability by placing code in a specific format on a USB device and inserting it into an affected Cisco device. A successful exploit could allow the attacker to execute the code with root privileges on the underlying OS of the affected device.
Cisco
Cisco IOS XE Software Arbitrary Code Execution Vulnerability
vendor_cisco·2019-09-25·CVSS 6.2
CVE-2019-12672 [MEDIUM] CWE-59 Cisco IOS XE Software Arbitrary Code Execution Vulnerability
Cisco IOS XE Software Arbitrary Code Execution Vulnerability
A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker with physical access to an affected device to execute arbitrary code on the underlying operating system (OS) with root privileges.
The vulnerability is due to insufficient file location validation. An attacker could exploit this vulnerability by placing code in a specific format on a USB device and inserting it into an affected Cisco device. A successful exploit could allow the attacker to execute the code with root privileges on the underlying OS of the affected device.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at t
Cisco
Cisco IOS XE Software Arbitrary Code Execution Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-12672 Cisco IOS XE Software Arbitrary Code Execution Vulnerability
CVE-2019-12672: Cisco IOS XE Software Arbitrary Code Execution Vulnerability
A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker with physical access to an affected device to execute arbitrary code on the underlying operating system (OS) with root privileges. The vulnerability is due to insufficient file location validation. An attacker could exploit this vulnerability by placing code in a specific format on a USB device and inserting it into an affected Cisco device. A successful exploit could allow the attacker to execute the code with root privileges on the underlying OS of the affected device. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-59, CWE-59
Bug IDs: CSCvg18064
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-09-25
Published