CVE-2019-1794
published 2019-04-18CVE-2019-1794: A vulnerability in the search path processing of Cisco Directory Connector could allow an authenticated, local attacker to load a binary of their choosing. The…
PriorityP422medium5.1CVSS 3.1
AVLACLPRHUINSUCLIHAN
EPSS
0.38%
30.5th percentile
A vulnerability in the search path processing of Cisco Directory Connector could allow an authenticated, local attacker to load a binary of their choosing. The vulnerability is due to uncontrolled search path elements. An attacker could exploit this vulnerability by placing a binary of their choosing earlier in the search path utilized by Cisco Directory Connector to locate and load required resources.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_directory_connector | — | — |
| cisco | directory_connector_search_order | — | — |
| cisco | meeting_server | — | — |
CVSS provenance
nvdv3.15.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
nvdv3.05.1MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
vendor_cisco5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Directory Connector Search Order Hijacking Vulnerability
vendor_cisco·2019-04-17·CVSS 5.1
CVE-2019-1794 [MEDIUM] CWE-427 Cisco Directory Connector Search Order Hijacking Vulnerability
Cisco Directory Connector Search Order Hijacking Vulnerability
A vulnerability in the search path processing of Cisco Directory Connector could allow an authenticated, local attacker to load a binary of their choosing.
The vulnerability is due to uncontrolled search path elements. An attacker could exploit this vulnerability by placing a binary of their choosing earlier in the search path utilized by Cisco Directory Connector to locate and load required resources.
There are workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190417-cdc-hijack
Cisco
Cisco Directory Connector Search Order Hijacking Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1794 Cisco Directory Connector Search Order Hijacking Vulnerability
CVE-2019-1794: Cisco Directory Connector Search Order Hijacking Vulnerability
A vulnerability in the search path processing of Cisco Directory Connector could allow an authenticated, local attacker to load a binary of their choosing. The vulnerability is due to uncontrolled search path elements. An attacker could exploit this vulnerability by placing a binary of their choosing earlier in the search path utilized by Cisco Directory Connector to locate and load required resources. There are
CVSS: 3.0
CWE: CWE-427, CWE-427
Bug IDs: CSCvk22605
GHSA
GHSA-m57f-9997-gm6m: A vulnerability in the search path processing of Cisco Directory Connector could allow an authenticated, local attacker to load a binary of their choo
ghsa_unreviewed·2022-05-13
CVE-2019-1794 [MEDIUM] CWE-427 GHSA-m57f-9997-gm6m: A vulnerability in the search path processing of Cisco Directory Connector could allow an authenticated, local attacker to load a binary of their choo
A vulnerability in the search path processing of Cisco Directory Connector could allow an authenticated, local attacker to load a binary of their choosing. The vulnerability is due to uncontrolled search path elements. An attacker could exploit this vulnerability by placing a binary of their choosing earlier in the search path utilized by Cisco Directory Connector to locate and load required resources.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-04-18
Published