SB2019082606 - Privilege escalation in Cisco RoomOS



SB2019082606 - Privilege escalation in Cisco RoomOS

Published: August 26, 2019

Security Bulletin ID SB2019082606
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2019-12622)

The vulnerability allows a remote attacker to write files to the underlying filesystem

The vulnerability exists due to insufficient permission restrictions on a specific process. A local authenticated attacker can log in to an affected device with remote support credentials, initiate the specific process on the device, send crafted data to that process and write files to the underlying file system with root privileges.


Remediation

Install update from vendor's website.