SB2019092529 - Multiple vulnerabilities in Nextcloud ios



SB2019092529 - Multiple vulnerabilities in Nextcloud ios

Published: September 25, 2019 Updated: August 8, 2020

Security Bulletin ID SB2019092529
Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) OS Command Injection (CVE-ID: CVE-2019-12650)

The vulnerability allows a remote authenticated user to execute arbitrary code.

Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabilities, see the Details section of this advisory.


2) OS Command Injection (CVE-ID: CVE-2019-12651)

The vulnerability allows a remote authenticated user to execute arbitrary code.

Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabilities, see the Details section of this advisory.


Remediation

Install update from vendor's website.