Improper access control in Cisco IOS - CVE-2019-12670

 

Improper access control in Cisco IOS - CVE-2019-12670

Published: September 26, 2019


Vulnerability identifier: #VU21352
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12670
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to insufficient file permissions in the filesystem. A local authenticated user can bypass implemented security restrictions, modify files, remove container protections and perform file actions outside the namespace of the container.

Affected software

Cisco IOS

How to mitigate CVE-2019-12670

Install updates from vendor's website.

Cisco IOS - update to 16.11.1

External References

Related Security Bulletins