OS command injection in Cisco Systems, Inc products - CVE-2019-1839

 

OS command injection in Cisco Systems, Inc products - CVE-2019-1839

Published: August 23, 2019 / Updated: August 26, 2019


Vulnerability identifier: #VU20381
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1839
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to execute commands on the underlying Linux shell.

The vulnerability exists due to insufficient validation of user-supplied input. A local authenticated user can supply various CLI commands with crafted arguments, run arbitrary commands and take over the target system.


Affected software

Cisco Remote PHY Shelf 7200
Cisco Remote PHY 220
Cisco Remote PHY 120

How to mitigate CVE-2019-1839

Install updates from vendor's website.

Cisco Remote PHY Shelf 7200 - update to 1.2
Cisco Remote PHY 220 - update to 3.1
Cisco Remote PHY 120 - update to 6.4

External References

Related Security Bulletins