Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-1794

Опубликовано: 18 апр. 2019
Источник: nvd
CVSS3: 5.1
CVSS3: 5.1
CVSS2: 3.6
EPSS Низкий

Описание

A vulnerability in the search path processing of Cisco Directory Connector could allow an authenticated, local attacker to load a binary of their choosing. The vulnerability is due to uncontrolled search path elements. An attacker could exploit this vulnerability by placing a binary of their choosing earlier in the search path utilized by Cisco Directory Connector to locate and load required resources.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:meeting_server:2.2:*:*:*:*:*:*:*

EPSS

Процентиль: 20%
0.00066
Низкий

5.1 Medium

CVSS3

5.1 Medium

CVSS3

3.6 Low

CVSS2

Дефекты

CWE-427
CWE-427

Связанные уязвимости

CVSS3: 5.1
github
больше 3 лет назад

A vulnerability in the search path processing of Cisco Directory Connector could allow an authenticated, local attacker to load a binary of their choosing. The vulnerability is due to uncontrolled search path elements. An attacker could exploit this vulnerability by placing a binary of their choosing earlier in the search path utilized by Cisco Directory Connector to locate and load required resources.

CVSS3: 5.1
fstec
почти 7 лет назад

Уязвимость приложения для синхронизации идентификаторов в облаке Cisco Directory Connector, связанная с ошибками механизма проверки пути поиска, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 20%
0.00066
Низкий

5.1 Medium

CVSS3

5.1 Medium

CVSS3

3.6 Low

CVSS2

Дефекты

CWE-427
CWE-427