SB2019082605 - Privilege escalation in Cisco Remote PHY
Published: August 26, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) OS command injection (CVE-ID: CVE-2019-1839)
The vulnerability allows a local attacker to execute commands on the underlying Linux shell.
The vulnerability exists due to insufficient validation of user-supplied input. A local authenticated user can supply various CLI commands with crafted arguments, run arbitrary commands and take over the target system.
Remediation
Install update from vendor's website.