CVE-2019-14259
Last modified
CVE-2019-14259 is a vulnerability of currently unknown severity. On the Polycom Obihai Obi1022 VoIP phone with firmware 5.1.11, a command injection (missing input validation) issue in the NTP server IP address field for the "Time Service Settings web" interface allows an authenticated remote attacker in the same network to trigger OS commands via shell commands in a POST request.. EPSS estimates a 2.80% chance of exploitation in the next 30 days.
Description
On the Polycom Obihai Obi1022 VoIP phone with firmware 5.1.11, a command injection (missing input validation) issue in the NTP server IP address field for the "Time Service Settings web" interface allows an authenticated remote attacker in the same network to trigger OS commands via shell commands in a POST request.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Polycom | Obihai Obi1022 Firmware | 5.1.11 |
References
- https://www.sit.fraunhofer.de/fileadmin/dokumente/CVE/Advisory_Obihai_Obi1002.pdf?_=1563787869Exploit, Third Party Advisory
- https://www.sit.fraunhofer.de/fileadmin/dokumente/CVE/Advisory_Obihai_Obi1002.pdf?_=1563787869Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-14259?
How severe is CVE-2019-14259?
How do I fix CVE-2019-14259?
Are you affected by CVE-2019-14259?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
