First published: Wed Sep 25 2019(Updated: )
A vulnerability in the Cisco TrustSec (CTS) Protected Access Credential (PAC) provisioning module of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of attributes in RADIUS messages. An attacker could exploit this vulnerability by sending a malicious RADIUS message to an affected device while the device is in a specific state.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE | =16.6.4 | |
Cisco IOS XE | =16.12.1 | |
Cisco Catalyst C9300-24P | ||
Cisco Catalyst C9300-24P | ||
Cisco Catalyst 9300 Series | ||
Cisco Catalyst 9300 Series | ||
Cisco Catalyst C9300-24T | ||
Cisco Catalyst C9300-24T | ||
Cisco Catalyst C9300-24U | ||
Cisco Catalyst C9300-24U | ||
Cisco Catalyst 9300-24UX-A | ||
Cisco Catalyst 9300-24UX-E | ||
Cisco Catalyst 9300-48P-A | ||
Cisco Catalyst 9300-48P-E | ||
Cisco Catalyst 9300 Series | ||
Cisco Catalyst 9300 Series | ||
Cisco Catalyst 9300-48T-A | ||
Cisco Catalyst 9300-48T-E | ||
Cisco Catalyst 9300-48U-A | ||
Cisco Catalyst 9300-48U-E | ||
Cisco Catalyst C9300 Series | ||
Cisco Catalyst 9300-48U-E | ||
Cisco Catalyst 9300-48UXM-A | ||
Cisco Catalyst 9300-48UXM-E | ||
Cisco Catalyst C9300L-24P-4G | ||
Cisco Catalyst C9300L-24P-4G | ||
Cisco Catalyst 9300L-24P-4X-A | ||
Cisco Catalyst 9300L-24P-4X-E | ||
Cisco Catalyst 9300L-24T-4G | ||
Cisco Catalyst 9300L-24T-4G | ||
Cisco Catalyst 9300L-24T-4X-A | ||
Cisco Catalyst 9300L-24T-4X-E | ||
Cisco Catalyst C9300L-48P-4G | ||
Cisco Catalyst C9300L-48P-4G | ||
Cisco Catalyst C9300L-48P-4X | ||
Cisco Catalyst C9300L-48P-4X | ||
Cisco Catalyst C9300L-48T-4G | ||
Cisco Catalyst C9300L-48T-4G | ||
Cisco Catalyst C9300L-48T-4X | ||
Cisco Catalyst C9300L-48T-4X | ||
Cisco Catalyst 9300L Stack | ||
Cisco Catalyst C9500-12Q-A | ||
Cisco Catalyst 9500 | ||
Cisco Catalyst C9500-16X-A | ||
Cisco Catalyst 9500 Series | ||
Cisco Catalyst C9500-24Q-A | ||
Cisco Catalyst C9500-24Q-E | ||
Cisco Catalyst 9500-40X-A | ||
Cisco Catalyst 9500-40X-E | ||
Cisco cBR-8 Converged Broadband Routers |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Cisco TrustSec (CTS) PAC provisioning module vulnerability is CVE-2019-12663.
The severity of CVE-2019-12663 is high with a CVSS score of 8.6.
This vulnerability affects Cisco IOS XE Software versions 16.6.4 and 16.12.1.
The vulnerability could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition by causing a reload of the affected device.
To fix CVE-2019-12663, update your Cisco IOS XE Software to a fixed software release.