A vulnerability in Cisco RoomOS Software could allow an authenticated, local attacker to write files to the underlying filesystem with root privileges. The vulnerability is due to insufficient permission restrictions on a specific process. An attacker could exploit this vulnerability by logging in to an affected device with remote support credentials and initiating the specific process on the device and sending crafted data to that process. A successful exploit could allow the attacker to write files to the underlying file system with root privileges.
Related Posts
- CVE-2011-3269 (25xxn_firmware, 6500e_firmware, c510_firmware, c520_firmware, c522_firmware, c524_firmware, c530_firmware, c532_firmware, c534_firmware, c540_firmware, c546_firmware, c734_firmware, c736_firmware, c760_firmware, c762_firmware, c770_firmware, c772_firmware, c782_firmware, c789_firmware, c792e_firmware, c920_firmware, c925de_firmware, c935dn_firmware, c950_firmware, e120_firmware, e230_firmware, e232_firmware, e234_firmware, e234n_firmware, e238_firmware, e240_firmware, e240n_firmware, e250_firmware, e260_firmware, e330_firmware, e332n_firmware, e340_firmware, e342_firmware, e350_firmware, e360_firmware, e450_firmware, e460_firmware, e462_firmware, t440_firmware, t640_firmware, t642_firmware, t644_firmware, t650_firmware, t652_firmware, t654_firmware, t656_firmware, w840_firmware, w850_firmware, x264_firmware, x34x_firmware, x36x_firmware, x422_firmware, x46x_firmware, x543_firmware, x544_firmware, x546_firmware, x548de_firmware, x642_firmware, x644_firmware, x646_firmware, x650_firmware, x734_firmware, x736_firmware, x738_firmware, x772e_firmware, x782e_firmware, x792de_firmware, x850_firmware, x852_firmware, x854_firmware, x860_firmware, x862_firmware, x864_firmware, x925de_firmware, x940e_firmware, x945e_firmware, x950_firmware, x952_firmware, x954_firmware)
Lexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a hidden email address in a Scan To Email shortcut. View…
- CVE-2018-18894 (6500e_firmware, c748_firmware, c79x_firmware, c925_firmware, c95x_firmware, cs41x_firmware, cs51x_firmware, cs748_firmware, cs796_firmware, cx410_firmware, cx510_firmware, m3150_firmware, m5155_firmware, m5163_firmware, m5170_firmware, ms610de_firmware, ms610dte_firmware, ms810de_firmware, ms812de_firmware, ms91x_firmware, mx410_firmware, mx510_firmware, mx511_firmware, mx610_firmware, mx611_firmware, mx6500e_firmware, mx71x_firmware, mx81x_firmware, mx91x_firmware, sm91x_firmware, x46x_firmware, x548_firmware, x65x_firmware, x73x_firmware, x74x_firmware, x792_firmware, x86x_firmware, x925_firmware, x95x_firmware, xc2132_firmware, xm1145_firmware, xm3150_firmware, xm51xx_firmware, xm71xx_firmware, xs478_firmware, xs548_firmware, xs79x_firmware, xs925_firmware, xs95x_firmware)
Certain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server. View Full Alert
- CVE-2019-10527 (apq8009_firmware, apq8017_firmware, apq8053_firmware, apq8096au_firmware, apq8098_firmware, bitra_firmware, ipq6018_firmware, ipq8074_firmware, kamorta_firmware, mdm9150_firmware, mdm9205_firmware, mdm9206_firmware, mdm9207c_firmware, mdm9607_firmware, mdm9640_firmware, mdm9650_firmware, msm8905_firmware, msm8909_firmware, msm8909w_firmware, msm8917_firmware, msm8920_firmware, msm8937_firmware, msm8940_firmware, msm8953_firmware, msm8996_firmware, msm8996au_firmware, msm8998_firmware, nicobar_firmware, qca4531_firmware, qca6574au_firmware, qca8081_firmware, qcm2150_firmware, qcn7605_firmware, qcn7606_firmware, qcs404_firmware, qcs405_firmware, qcs605_firmware, qcs610_firmware, qm215_firmware, rennell_firmware, sa415m_firmware, sa515m_firmware, sa6155p_firmware, saipan_firmware, sc7180_firmware, sc8180x_firmware, sda660_firmware, sda845_firmware, sdm429_firmware, sdm429w_firmware, sdm439_firmware, sdm450_firmware, sdm630_firmware, sdm632_firmware, sdm636_firmware, sdm660_firmware, sdm670_firmware, sdm710_firmware, sdm845_firmware, sdm850_firmware, sdx20_firmware, sdx24_firmware, sdx55_firmware, sm6150_firmware, sm7150_firmware, sm8150_firmware, sm8250_firmware, sxr1130_firmware, sxr2130_firmware)
u'SMEM partition can be manipulated in case of any compromise on HLOS, thus resulting in access to memory outside of SMEM address range which could lead to memory corruption' in…