OS command injection in Cisco Systems, Inc products - CVE-2019-1839
Published: August 23, 2019 / Updated: August 26, 2019
Vulnerability details
The vulnerability allows a local attacker to execute commands on the underlying Linux shell.
The vulnerability exists due to insufficient validation of user-supplied input. A local authenticated user can supply various CLI commands with crafted arguments, run arbitrary commands and take over the target system.
Affected software
Cisco Remote PHY 220
Cisco Remote PHY 120
How to mitigate CVE-2019-1839
Cisco Remote PHY 220 - update to 3.1
Cisco Remote PHY 120 - update to 6.4