First published: Wed Sep 25 2019(Updated: )
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | =16.11.1 | |
Cisco IOS XE | =16.6.5 | |
Cisco 1100-4p Integrated Services Router | ||
Cisco 1100-8p Integrated Services Router | ||
Cisco 1101-4p Integrated Services Router | ||
Cisco 1109-2p | ||
Cisco 1109-4p Integrated Services Router | ||
Cisco 1111x-8p Integrated Services Router | ||
Cisco ASR 1001-X | ||
Cisco ASR 1002-HX-RF | ||
Cisco ASR 1006-X | ||
Cisco ASR 1009-X | ||
Cisco Catalyst 3650-12x48UQ | ||
Cisco Catalyst 3650-12x48UR | ||
Cisco Catalyst 3650-12X48UZ | ||
Cisco Catalyst 3650 24 Port PoE Switch (WS-C3650-24PD) | ||
Cisco Catalyst 3650-24PDM | ||
Cisco Catalyst 3650-48FQ | ||
Cisco Catalyst 3650-48FQM Switch | ||
Cisco Catalyst 3650-8X24UQ | ||
Cisco Catalyst 3850-12X48U-E | ||
Cisco Catalyst 3850-24U | ||
Cisco Catalyst 3850-24XS | ||
Cisco Catalyst 3850-24XU | ||
Cisco Catalyst 3850-48U | ||
Cisco Catalyst 3850-48XS | ||
Cisco Catalyst 3850-NM-2-40G | ||
Cisco Catalyst 3850-NM-8-10G | ||
Cisco Catalyst 9800-40 | ||
Cisco Catalyst 9800-80 | ||
Cisco Catalyst 9800-L | ||
Cisco Catalyst 9800-L firmware | ||
Cisco Catalyst 9800-L | ||
Cisco Catalyst 9800-L | ||
Cisco Catalyst C9200-24P | ||
Cisco Catalyst C9200-24T | ||
Cisco Catalyst C9200-48P | ||
Cisco Catalyst C9200-48T | ||
Cisco Catalyst C9200L-24P-4G | ||
Cisco Catalyst C9200L-24P-4X | ||
Cisco catalyst c9200l-24pxg-2y | ||
Cisco Catalyst C9200L-24PXG-4X | ||
Cisco Catalyst C9200L-24T-4G | ||
Cisco Catalyst C9200L-24T-4X | ||
Cisco Catalyst C9200L-48P-4G | ||
Cisco Catalyst C9200L-48P-4X | ||
Cisco Catalyst C9200L-48PXG-2Y | ||
Cisco Catalyst C9200L-48PXG-4X | ||
Cisco Catalyst C9200L-48T-4G | ||
Cisco Catalyst C9200L-48T-4X | ||
Cisco Catalyst C9300-24P | ||
Cisco Catalyst C9300-24S | ||
Cisco Catalyst 9300-24T-A | ||
Cisco Catalyst C9300-24U | ||
Cisco Catalyst C9300-24UX | ||
Cisco Catalyst C9300-48P | ||
Cisco Catalyst C9300-48S | ||
Cisco Catalyst C9300-48T | ||
Cisco Catalyst 9300-48U | ||
Cisco Catalyst C9300 Series | ||
Cisco Catalyst C9300-48UXM | ||
Cisco Catalyst C9300L-24P-4G | ||
Cisco Catalyst C9300L-24P-4X | ||
Cisco Catalyst 9300L-24T-4G | ||
Cisco Catalyst C9300L-24T-4X | ||
Cisco Catalyst C9300L-48P-4G | ||
Cisco Catalyst C9300L-48P-4X | ||
Cisco Catalyst C9300L-48T-4G | ||
Cisco Catalyst C9300L-48T-4X | ||
Cisco Catalyst 9500 | ||
Cisco Catalyst 9500 Series | ||
Cisco Catalyst C9500-24Q | ||
Cisco Catalyst C9500-24Y4C | ||
Cisco Catalyst C9500-32C | ||
Cisco Catalyst C9500-32QC | ||
Cisco Catalyst 9500-40X-E | ||
Cisco Catalyst C9500-48Y4C | ||
Cisco Integrated Services Virtual Router Firmware | ||
Cisco IOS XE | =17.1.1 | |
Cisco Cloud Services Router 1000V |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12650 has been rated as high severity due to its potential to allow authenticated remote command execution with elevated privileges.
To fix CVE-2019-12650, upgrade your Cisco IOS XE Software to a version that includes the necessary security patches.
CVE-2019-12650 affects multiple versions of Cisco IOS XE Software, specifically versions 16.6.5 and 16.11.1.
CVE-2019-12650 is categorized as a command injection vulnerability in the web-based user interface of Cisco IOS XE Software.
An attacker exploiting CVE-2019-12650 could execute arbitrary commands on the affected device, potentially leading to full system compromise.