VDB
CVE-2019-1794
CVE-2019-1794
PUBLISHED
CVSS 5.099999904632568 MEDIUM
A vulnerability in the search path processing of Cisco Directory Connector could allow an authenticated, local attacker to load a binary of their choosing. The vulnerability is due to uncontrolled search path elements. An attacker could exploit this vulnerability by placing a binary of their choosing earlier in the search path utilized by Cisco Directory Connector to locate and load required resources.
EPSS 0.07% · 20.6th percentile
Risk Scores
CVSS 3.0
5.099999904632568
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
EPSS Score
0.07%
20.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | meeting_server | 2.2 |
| Cisco | Cisco Directory Connector | 2.2 |
Exploit Intelligence
Timeline
- Apr 17, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score