A vulnerability in the software update feature of Cisco Industrial Network Director could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is due to improper validation of files uploaded to the affected application. An attacker could exploit this vulnerability by authenticating to the affected system using administrator privileges and uploading an arbitrary file. A successful exploit could allow the attacker to execute arbitrary code with elevated privileges.
Metrics
Affected Vendors & Products
References
History
Thu, 21 Nov 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: cisco
Published: 2019-06-05T16:25:22.859291Z
Updated: 2024-11-20T17:17:52.861Z
Reserved: 2018-12-06T00:00:00
Link: CVE-2019-1861

Updated: 2024-08-04T18:28:42.868Z

Status : Modified
Published: 2019-06-05T17:29:00.490
Modified: 2024-11-21T04:37:33.463
Link: CVE-2019-1861

No data.