CVE-2019-15996
Cisco DNA Spaces: Connector Privilege Escalation Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. The vulnerability is due to insufficient restrictions during the execution of an affected CLI command. An attacker could exploit this vulnerability by leveraging the insufficient restrictions to modify sensitive files. A successful exploit could allow the attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root.
Una vulnerabilidad en Cisco DNA Spaces: Connector, podría permitir a un atacante local autenticado elevar los privilegios y ejecutar comandos arbitrarios en el sistema operativo subyacente como root. La vulnerabilidad es debido a restricciones insuficientes durante la ejecución de un comando de la CLI afectado. Un atacante podría explotar esta vulnerabilidad al aprovechar las restricciones insuficientes para modificar archivos confidenciales. Una explotación con éxito podría permitir al atacante elevar los privilegios y ejecutar comandos arbitrarios en el sistema operativo subyacente como root.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2019-09-06 CVE Reserved
- 2019-11-26 CVE Published
- 2023-03-08 EPSS Updated
- 2024-11-20 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Dna Spaces: Connector Search vendor "Cisco" for product "Dna Spaces: Connector" | < 2.1 Search vendor "Cisco" for product "Dna Spaces: Connector" and version " < 2.1" | - |
Affected
|