CVE-2019-12624: Cisco IOS XE NGWC Legacy Wireless Device Manager GUI Cross-Site Request Forgery Vulnerability
A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected device by using a web browser and with the privileges of the user.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-12624?
CVE-2019-12624 is a vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) that allows for a cross-site request forgery (CSRF) attack.
How does CVE-2019-12624 affect Cisco IOS XE?
CVE-2019-12624 affects Cisco IOS XE versions 3.0.xe to 3.11.xe, allowing unauthenticated remote attackers to perform arbitrary actions on an affected device.
What is the severity of CVE-2019-12624?
CVE-2019-12624 has a severity rating of 8.8 (high).
How can I fix CVE-2019-12624?
To fix CVE-2019-12624, Cisco recommends upgrading to a fixed release of Cisco IOS XE software.
Where can I find more information about CVE-2019-12624?
More information about CVE-2019-12624 can be found in Cisco's security advisory.