Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-1911

Опубликовано: 06 июл. 2019
Источник: nvd
CVSS3: 5.3
CVSS3: 7.8
CVSS2: 4.6
EPSS Низкий

Описание

A vulnerability in the CLI of Cisco Unified Communications Domain Manager (Cisco Unified CDM) Software could allow an authenticated, local attacker to escape the restricted shell. The vulnerability is due to insufficient input validation of shell commands. An attacker could exploit this vulnerability by executing crafted commands in the shell. A successful exploit could allow the attacker to escape the restricted shell and access commands in the context of the restricted shell user, which does not have root privileges.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:hosted_collaboration_solution:*:*:*:*:*:*:*:*
Версия до 11.5\(3\)pb3 (включая)

EPSS

Процентиль: 17%
0.00055
Низкий

5.3 Medium

CVSS3

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-216
CWE-216

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

A vulnerability in the CLI of Cisco Unified Communications Domain Manager (Cisco Unified CDM) Software could allow an authenticated, local attacker to escape the restricted shell. The vulnerability is due to insufficient input validation of shell commands. An attacker could exploit this vulnerability by executing crafted commands in the shell. A successful exploit could allow the attacker to escape the restricted shell and access commands in the context of the restricted shell user, which does not have root privileges.

CVSS3: 5.3
fstec
больше 6 лет назад

Уязвимость интерфейса командной строки системы обработки вызовов Cisco Unified Communications Domain Manager, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 17%
0.00055
Низкий

5.3 Medium

CVSS3

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-216
CWE-216