CVE-2019-12650: Cisco IOS XE Software Web UI Command Injection Vulnerabilities
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12650?
CVE-2019-12650 has been rated as high severity due to its potential to allow authenticated remote command execution with elevated privileges.
How do I fix CVE-2019-12650?
To fix CVE-2019-12650, upgrade your Cisco IOS XE Software to a version that includes the necessary security patches.
Who is affected by CVE-2019-12650?
CVE-2019-12650 affects multiple versions of Cisco IOS XE Software, specifically versions 16.6.5 and 16.11.1.
What type of vulnerability is CVE-2019-12650?
CVE-2019-12650 is categorized as a command injection vulnerability in the web-based user interface of Cisco IOS XE Software.
What could an attacker do with CVE-2019-12650?
An attacker exploiting CVE-2019-12650 could execute arbitrary commands on the affected device, potentially leading to full system compromise.