CVE-2019-1765
published 2019-03-22CVE-2019-1765: A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an…
PriorityP341medium6.5CVSS 3.0
AVNACLPRLUINSUCNIHAN
EPSS
1.37%
68.8th percentile
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an authenticated, remote attacker to write arbitrary files to the filesystem. The vulnerability is due to insufficient input validation and file-level permissions. An attacker could exploit this vulnerability by uploading invalid files to an affected device. A successful exploit could allow the attacker to write files in arbitrary locations on the filesystem. This vulnerability affects Cisco IP Phone 8800 Series products running a SIP Software release prior to 11.0(5) for Wireless IP Phone 8821 and 8821-EX; and 12.5(1)SR1 for the IP Conference Phone 8832 and the rest of the IP Phone 8800 Series.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ip_conference_phone_8832_and_the_rest_of_the_ip_phone_8800_series | >= unspecified < 12.5(1)SR1 | 12.5(1)SR1 |
| cisco | cisco_wireless_ip_phone_8821_and_8821-ex | >= unspecified < 11.0(5) | 11.0(5) |
| cisco | ip_conference_phone_8832_firmware | < 12.5\(1\)sr1 | 12.5\(1\)sr1 |
| cisco | ip_phone_8800_firmware | < 12.5\(1\)sr1 | 12.5\(1\)sr1 |
| cisco | ip_phone_8800_series_path | — | — |
| cisco | ip_phone_8821-ex_firmware | < 11.0\(5\) | 11.0\(5\) |
| cisco | ip_phone_8821_firmware | < 11.0\(5\) | 11.0\(5\) |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_cisco8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IP Phone 8800 Series Path Traversal Vulnerability
vendor_cisco·2019-03-20·CVSS 8.1
CVE-2019-1765 [HIGH] CWE-22 Cisco IP Phone 8800 Series Path Traversal Vulnerability
Cisco IP Phone 8800 Series Path Traversal Vulnerability
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an authenticated, remote attacker to write arbitrary files to the filesystem.
The vulnerability is due to insufficient input validation and file-level permissions. An attacker could exploit this vulnerability by uploading invalid files to an affected device. A successful exploit could allow the attacker to write files in arbitrary locations on the filesystem.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/Cisc
Cisco
Cisco IP Phone 8800 Series Path Traversal Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1765 Cisco IP Phone 8800 Series Path Traversal Vulnerability
CVE-2019-1765: Cisco IP Phone 8800 Series Path Traversal Vulnerability
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an authenticated, remote attacker to write arbitrary files to the filesystem. The vulnerability is due to insufficient input validation and file-level permissions. An attacker could exploit this vulnerability by uploading invalid files to an affected device. A successful exploit could allow the attacker to write files in arbitrary locations on the filesystem. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-22, CWE-22
Bug IDs: CSCvn56213, CSCvo57138
GHSA
GHSA-2473-cf85-p25m: A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an auth
ghsa_unreviewed·2022-05-13
CVE-2019-1765 [MEDIUM] CWE-22 GHSA-2473-cf85-p25m: A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an auth
A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an authenticated, remote attacker to write arbitrary files to the filesystem. The vulnerability is due to insufficient input validation and file-level permissions. An attacker could exploit this vulnerability by uploading invalid files to an affected device. A successful exploit could allow the attacker to write files in arbitrary locations on the filesystem. This vulnerability affects Cisco IP Phone 8800 Series products running a SIP Software release prior to 11.0(5) for Wireless IP Phone 8821 and 8821-EX; and 12.5(1)SR1 for the IP Conference Phone 8832 and the rest of the IP Phone 8800 Series.
No detection rules found.
No public exploits indexed.
HackerOne
Docker image with FPM is vulnerable to CVE-2019-11043
hackerone·2020-03-14·CVSS 8.7
CVE-2019-11043 [HIGH] Docker image with FPM is vulnerable to CVE-2019-11043
Docker image with FPM is vulnerable to CVE-2019-11043
The CVE-2019-11043 vulnerability can be exploited in the latest nextcloud:fpm image.
This is due to the specific nginx configuration recommended for nextcloud:
https://github.com/nextcloud/docker#base-version---fpm
https://github.com/nextcloud/documentation/blob/master/admin_manual/installation/nginx.rst
https://github.com/nextcloud/docker/blob/master/.examples/docker-compose/with-nginx-proxy/mariadb/fpm/web/nginx.conf
Here's the exploit: https://github.com/neex/phuip-fpizdam
Sample exploit run:
# ./phuip-fpizdam http://localhost:8080/ocs/v2.php
2019/10/22 19:36:29 Base status code is 200
2019/10/22 19:36:30 Status code 502 for qsl=1765, adding as a candidate
2019/10/22 19:36:31 The target is probably vulnerable. Possible QSLs: [175
Bugzilla
CVE-2019-8696 cups: stack-buffer-overflow in libcups's asn1_get_packed function
bugzilla·2019-08-07·CVSS 8.8
CVE-2019-8696 [HIGH] CVE-2019-8696 cups: stack-buffer-overflow in libcups's asn1_get_packed function
CVE-2019-8696 cups: stack-buffer-overflow in libcups's asn1_get_packed function
A stack-buffer-overflow was found in libcups's asn1_get_packed function
Discussion:
Acknowledgments:
Name: Apple Product Security
Upstream: Stephan Zeisberg (Security Research Labs)
---
References:
https://github.com/apple/cups/releases/tag/v2.2.12
https://support.apple.com/en-in/HT210348
---
Upstream commit:
https://github.com/apple/cups/commit/f24e6cf6a39300ad0c3726a41a4aab51ad54c109
---
Created cups tracking bugs for this issue:
Affects: fedora-all [bug 1742935]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:1765 https://access.redhat.com/errata/RHSA-2020:1765
---
This bug is now closed. Further updates for individual products will be
Bugzilla
CVE-2019-11717 Mozilla: Caret character improperly escaped in origins
bugzilla·2019-07-10·CVSS 5.3
CVE-2019-11717 [MEDIUM] CVE-2019-11717 Mozilla: Caret character improperly escaped in origins
CVE-2019-11717 Mozilla: Caret character improperly escaped in origins
A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-22/#CVE-2019-11717
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Tyson Smith
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:1764 https://access.redhat.com/errata/RHSA-2019:1764
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2019:1765 https://access.redhat.com/errata/RHSA-2019:1765
---
This issue has been addressed in t
Bugzilla
CVE-2019-11713 Mozilla: Use-after-free with HTTP/2 cached stream
bugzilla·2019-07-10·CVSS 9.8
CVE-2019-11713 [CRITICAL] CVE-2019-11713 Mozilla: Use-after-free with HTTP/2 cached stream
CVE-2019-11713 Mozilla: Use-after-free with HTTP/2 cached stream
A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still in use, resulting in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-22/#CVE-2019-11713
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Hanno Böck
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:1764 https://access.redhat.com/errata/RHSA-2019:1764
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2019:1765 https://access.redhat.com/errata/RHSA-2019:1765
---
This issue has been addressed in the following products:
Red Hat Enterpris
Bugzilla
CVE-2019-9811 Mozilla: Sandbox escape via installation of malicious language pack
bugzilla·2019-07-10·CVSS 8.3
CVE-2019-9811 [HIGH] CVE-2019-9811 Mozilla: Sandbox escape via installation of malicious language pack
CVE-2019-9811 Mozilla: Sandbox escape via installation of malicious language pack
As part of his winning Pwn2Own entry, Niklas Baumstark demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-22/#CVE-2019-9811
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Niklas Baumstark
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:1764 https://access.redhat.com/errata/RHSA-2019:1764
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2019:1765 https://access.redhat.com/errata/RHSA-2019:1765
---
This issu
Bugzilla
CVE-2019-11715 Mozilla: HTML parsing error can contribute to content XSS
bugzilla·2019-07-10·CVSS 6.1
CVE-2019-11715 [MEDIUM] CVE-2019-11715 Mozilla: HTML parsing error can contribute to content XSS
CVE-2019-11715 Mozilla: HTML parsing error can contribute to content XSS
Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-22/#CVE-2019-11715
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Linus Särud
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:1764 https://access.redhat.com/errata/RHSA-2019:1764
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2019:1765 https://access.redhat.com/errata/RHSA-2019:1765
---
This issue has been addressed in the followi
Bugzilla
CVE-2019-11712 Mozilla: Cross-origin POST requests can be made with NPAPI plugins by following 308 redirects
bugzilla·2019-07-10·CVSS 8.8
CVE-2019-11712 [HIGH] CVE-2019-11712 Mozilla: Cross-origin POST requests can be made with NPAPI plugins by following 308 redirects
CVE-2019-11712 Mozilla: Cross-origin POST requests can be made with NPAPI plugins by following 308 redirects
POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-22/#CVE-2019-11712
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Gregory Smiley (Security Compass)
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2019:1764 https://access.redhat.com/errata/RHSA-2019:1764
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2019:1765 https://ac
2019-03-22
Published