← Back to browse · API

CVE-2019-12630

Severity
MEDIUM
CVSS
6.5
EPSS
0.65846
Risk score
49.05
CISA KEV
No
PoC
No
Published
2019-10-02
Modified
2024-11-19
First seen
2026-08-07
Aliases
EUVD-2019-4221, GHSA-342J-57XR-35P2
Products
Cisco:Cisco Security Manager unspecified <n/a
Sources
euvd EUVD-2019-4221

Description

A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a malicious serialized Java object to a specific listener on an affected system. A successful exploit could allow the attacker to execute arbitrary commands on the device with the privileges of casuser.

References