SB2019082606 - Privilege escalation in Cisco RoomOS
Published: August 26, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2019-12622)
The vulnerability allows a remote attacker to write files to the underlying filesystem
The vulnerability exists due to insufficient permission restrictions on a specific process. A local authenticated attacker can log in to an affected device with remote support credentials, initiate the specific process on the device, send crafted data to that process and write files to the underlying file system with root privileges.
Remediation
Install update from vendor's website.