SB2019110803 - Privilege escalation in Cisco TelePresence Collaboration Endpoint, TelePresence Codec and RoomOS



SB2019110803 - Privilege escalation in Cisco TelePresence Collaboration Endpoint, TelePresence Codec and RoomOS

Published: November 8, 2019

Security Bulletin ID SB2019110803
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Input validation error (CVE-ID: CVE-2019-15288)

The vulnerability allows a remote attacker to escalate privileges to an unrestricted user of the restricted shell.

The vulnerability exists due to insufficient validation of user-supplied input in the CLI. A remote authenticated attacker can include specific arguments when opening an SSH connection to an affected device and gain unrestricted user access to the restricted shell of an affected device.

Note: This vulnerability affects Cisco RoomOS Software releases earlier than RoomOS September Drop 1 2019 that have the SSH feature enabled.


Remediation

Install update from vendor's website.