Lucene search

K
symantecSymantec Security ResponseSMNTC-110807
HistoryNov 06, 2019 - 12:00 a.m.

Multiple Cisco Products CVE-2019-15967 Local Security Bypass Vulnerability

2019-11-0600:00:00
Symantec Security Response
www.symantec.com
12

EPSS

0

Percentile

5.1%

Description

Multiple Cisco Products are prone to a local security-bypass vulnerability. An attacker may exploit this issue to bypass certain security restrictions and perform unauthorized actions. This may lead to further attacks. This issue is being tracked by Cisco Bug ID CSCvq29891.

Technologies Affected

  • Cisco RoomOS Software
  • Cisco TelePresence CE Software 8.0.0
  • Cisco TelePresence CE Software 8.0.1
  • Cisco TelePresence CE Software 8.1.0
  • Cisco TelePresence CE Software 8.3.7
  • Cisco TelePresence CE Software 9.1.1
  • Cisco TelePresence CE Software 9.2.1
  • Cisco TelePresence CE Software 9.3.1
  • Cisco TelePresence CE Software 9.4.1
  • Cisco TelePresence CE Software 9.5.1
  • Cisco TelePresence CE Software 9.5.3
  • Cisco TelePresence CE Software 9.6.1
  • Cisco TelePresence CE Software 9.7.1
  • Cisco TelePresence CE Software 9.8.0

Recommendations

Permit local access for trusted individuals only. Where possible, use restricted environments and restricted shells.
Ensure that only trusted users have local, interactive access to affected computers.

Run all software as a nonprivileged user with minimal access rights.
To limit the impact of latent vulnerabilities, configure servers and other applications to run as a non administrative user with minimal access rights.

Updates are available. Please see the references or vendor advisory for more information.

References

EPSS

0

Percentile

5.1%

Related for SMNTC-110807