First published: Wed Sep 25 2019(Updated: )
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS | =16.11.1 | |
Cisco Cloud Services Router 1000v Firmware | =17.1.1 | |
Cisco Cloud Services Router 1000v | ||
Cisco Integrated Services Virtual Router Firmware | =16.6.5 | |
Cisco Integrated Services Virtual Router |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12651 is a vulnerability in the web-based user interface (Web UI) of Cisco IOS XE Software that allows an authenticated remote attacker to execute commands with elevated privileges on the affected device.
CVE-2019-12651 has a severity rating of 8.8 (Critical).
Cisco IOS version 16.11.1 and Cisco Cloud Services Router 1000v Firmware version 17.1.1 are affected by CVE-2019-12651.
An attacker can exploit CVE-2019-12651 by gaining authenticated access to the web-based user interface and executing malicious commands with elevated privileges.
No, Cisco Integrated Services Virtual Router is not affected by CVE-2019-12651.