Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2237-2j5h-553w

Опубликовано: 15 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.7

Описание

A vulnerability in Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to elevate privileges to root on an affected device.

This vulnerability is due to improper access control on certain CLI commands. An attacker could exploit this vulnerability by running a series of crafted commands. A successful exploit could allow the attacker to elevate privileges to root. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

A vulnerability in Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to elevate privileges to root on an affected device.

This vulnerability is due to improper access control on certain CLI commands. An attacker could exploit this vulnerability by running a series of crafted commands. A successful exploit could allow the attacker to elevate privileges to root. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

EPSS

Процентиль: 5%
0.00025
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-27

Связанные уязвимости

CVSS3: 6.7
nvd
7 месяцев назад

A vulnerability in Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to improper access control on certain CLI commands. An attacker could exploit this vulnerability by running a series of crafted commands. A successful exploit could allow the attacker to elevate privileges to root. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

CVSS3: 6.7
fstec
около 2 лет назад

Уязвимость микропрограммного обеспечения устройства управления конференц-связью Cisco TelePresence Collaboration Endpoint (CE) и операционных систем Cisco RoomOS, связанная с недостатками разграничения доступа, позволяющая нарушителю повысить привилегии до получения root прав на уязвимом устройстве

EPSS

Процентиль: 5%
0.00025
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-27