CVE-2019-12669: Cisco IOS and IOS XE Software Change of Authorization Denial of Service Vulnerability
A vulnerability in the RADIUS Change of Authorization (CoA) code of Cisco TrustSec, a feature within Cisco IOS XE Software, could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of a malformed packet. An attacker could exploit this vulnerability by sending a malformed packet to an affected device. A successful exploit could allow the attacker to cause a DoS condition on the affected device.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-12669.
What is the severity of CVE-2019-12669?
The severity of CVE-2019-12669 is high with a severity value of 7.5.
What is the affected software for CVE-2019-12669?
The affected software for CVE-2019-12669 includes Cisco IOS XE Software versions 15.2(3)e, 15.2(3)e5, and 16.11.1.
What is the impact of CVE-2019-12669?
CVE-2019-12669 can allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
Is Cisco Catalyst 3560 vulnerable to CVE-2019-12669?
No, Cisco Catalyst 3560, 3560-e, and 3560-x are not vulnerable to CVE-2019-12669.