SB2019060528 - Input validation error in Industrial Network Director



SB2019060528 - Input validation error in Industrial Network Director

Published: June 5, 2019 Updated: August 8, 2020

Security Bulletin ID SB2019060528
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Input validation error (CVE-ID: CVE-2019-1861)

The vulnerability allows a remote privileged user to execute arbitrary code.

A vulnerability in the software update feature of Cisco Industrial Network Director could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is due to improper validation of files uploaded to the affected application. An attacker could exploit this vulnerability by authenticating to the affected system using administrator privileges and uploading an arbitrary file. A successful exploit could allow the attacker to execute arbitrary code with elevated privileges.


Remediation

Install update from vendor's website.