CVE-2019-1878 HIGH

CVE-2019-1878: Cisco TelePresence Endpoint Command Shell Injection Vulnerability

Vendor Cisco
Product Cisco TelePresence TC Software
Weakness CWE-78
Published June 20, 2019
Last update November 20, 2024

CVSS base score

7.5/10
Attack vector Adjacent
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

A vulnerability in the Cisco Discovery Protocol (CDP) implementation for the Cisco TelePresence Codec (TC) and Collaboration Endpoint (CE) Software could allow an unauthenticated, adjacent attacker to inject arbitrary shell commands that are executed by the device. The vulnerability is due to insufficient input validation of received CDP packets. An attacker could exploit this vulnerability by sending crafted CDP packets to an affected device. A successful exploit could allow the attacker to execute arbitrary shell commands or scripts on the targeted device.

Key dates

02Disclosure timeline

June 20, 2019 CVE published
November 20, 2024 Record updated