MEDIUM · 4.4

CVE-2019-15962

A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to write files to the /root directory of an affected device. The vuln...

Vulnerability Description

A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to write files to the /root directory of an affected device. The vulnerability is due to improper permission assignment. An attacker could exploit this vulnerability by logging in as the remotesupport user and writing files to the /root directory of an affected device.

CVSS Score

4.4

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
CiscoTelepresence Collaboration Endpoint7.3.18
CiscoWebex Board 55-
CiscoWebex Board 55S-
CiscoWebex Board 70-
CiscoWebex Board 70S-
CiscoWebex Board 85S-
CiscoWebex Room 55-
CiscoWebex Room 55 Dual-
CiscoWebex Room 70 Dual-
CiscoWebex Room 70 Dual G2-
CiscoWebex Room 70 Single-
CiscoWebex Room 70 Single G2-
CiscoWebex Room Kit-
CiscoWebex Room Kit Mini-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-15962?

CVE-2019-15962 is a vulnerability with a CVSS score of 4.4 (MEDIUM). A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to write files to the /root directory of an affected device. The vuln...

How severe is CVE-2019-15962?

CVE-2019-15962 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-15962?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Telepresence Collaboration Endpoint, Cisco Webex Board 55, Cisco Webex Board 55S, Cisco Webex Board 70, Cisco Webex Board 70S.