Rewterz

Rewterz Threat Advisory – CVE 2019-12817 – Linux Kernel Local Privilege Escalation Vulnerability

June 26, 2019
Rewterz

Rewterz Threat Alert – Malspam Campaigns Hide Infostealers in ISO Image Files

June 27, 2019

Rewterz Threat Advisory – CVE-2019-1620 – Cisco Data Center Network Manager Arbitrary File Upload and Remote Code Execution Vulnerability

Severity

High

Analysis summary

The vulnerability is due to incorrect permission settings in affected DCNM software. An attacker could exploit this vulnerability by uploading specially crafted data to the affected device. A successful exploit could allow the attacker to write arbitrary files on the filesystem and execute code with root privileges on the affected device.

Impact

Unauthorized system access

Affected Vendors

Cisco

Affected Products

Cisco Data Center Network Manager releases prior to Release 11.2(1).

Remediation

Update to patch DCNM Software Release 11.2(1).

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.