CVE-2019-1623
published 2019-06-20CVE-2019-1623: A vulnerability in the CLI configuration shell of Cisco Meeting Server could allow an authenticated, local attacker to inject arbitrary commands as the root…
PriorityP433medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.51%
39.8th percentile
A vulnerability in the CLI configuration shell of Cisco Meeting Server could allow an authenticated, local attacker to inject arbitrary commands as the root user. The vulnerability is due to insufficient input validation during the execution of a vulnerable CLI command. An attacker with administrator-level credentials could exploit this vulnerability by injecting crafted arguments during command execution. A successful exploit could allow the attacker to perform arbitrary code execution as root on an affected product.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_meeting_server | >= unspecified < 2.2.14 | 2.2.14 |
| cisco | meeting_server | — | — |
| cisco | meeting_server | >= 2.2.0 < 2.2.14 | 2.2.14 |
| cisco | meeting_server | >= 2.3.0 < 2.3.8 | 2.3.8 |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv3.06.7MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Meeting Server CLI Command Injection Vulnerability
vendor_cisco·2019-06-19·CVSS 6.7
CVE-2019-1623 [MEDIUM] CWE-77 Cisco Meeting Server CLI Command Injection Vulnerability
Cisco Meeting Server CLI Command Injection Vulnerability
A vulnerability in the CLI configuration shell of Cisco Meeting Server could allow an authenticated, local attacker to inject arbitrary commands as the root user.
The vulnerability is due to insufficient input validation during the execution of a vulnerable CLI command. An attacker with administrator-level credentials could exploit this vulnerability by injecting crafted arguments during command execution. A successful exploit could allow the attacker to perform arbitrary code execution as root on an affected product.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/
Cisco
Cisco Meeting Server CLI Command Injection Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1623 Cisco Meeting Server CLI Command Injection Vulnerability
CVE-2019-1623: Cisco Meeting Server CLI Command Injection Vulnerability
A vulnerability in the CLI configuration shell of Cisco Meeting Server could allow an authenticated, local attacker to inject arbitrary commands as the root user. The vulnerability is due to insufficient input validation during the execution of a vulnerable CLI command. An attacker with administrator-level credentials could exploit this vulnerability by injecting crafted arguments during command execution. A successful exploit could allow the attacker to perform arbitrary code execution as root on an affected product. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-77, CWE-77
Bug IDs: CSCvk42093
GHSA
GHSA-m4v2-gwgf-j2gq: A vulnerability in the CLI configuration shell of Cisco Meeting Server could allow an authenticated, local attacker to inject arbitrary commands as th
ghsa_unreviewed·2022-05-24
CVE-2019-1623 [HIGH] GHSA-m4v2-gwgf-j2gq: A vulnerability in the CLI configuration shell of Cisco Meeting Server could allow an authenticated, local attacker to inject arbitrary commands as th
A vulnerability in the CLI configuration shell of Cisco Meeting Server could allow an authenticated, local attacker to inject arbitrary commands as the root user. The vulnerability is due to insufficient input validation during the execution of a vulnerable CLI command. An attacker with administrator-level credentials could exploit this vulnerability by injecting crafted arguments during command execution. A successful exploit could allow the attacker to perform arbitrary code execution as root on an affected product.
No detection rules found.
No public exploits indexed.
2019-06-20
Published