Permissions, Privileges, and Access Controls in Cisco RoomOS - CVE-2019-12622

 

Permissions, Privileges, and Access Controls in Cisco RoomOS - CVE-2019-12622

Published: August 23, 2019 / Updated: August 26, 2019


Vulnerability identifier: #VU20382
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12622
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to write files to the underlying filesystem

The vulnerability exists due to insufficient permission restrictions on a specific process. A local authenticated attacker can log in to an affected device with remote support credentials, initiate the specific process on the device, send crafted data to that process and write files to the underlying file system with root privileges.


Affected software

Cisco RoomOS

How to mitigate CVE-2019-12622

Install updates from vendor's website.

Cisco RoomOS - addressed in versions ce 9.7.3, ce 9.8.0

External References

Related Security Bulletins