CVE-2019-12671: Cisco IOS XE Software Consent Token Bypass Vulnerability
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execute commands on the underlying operating system (OS). The vulnerability is due to insufficient enforcement of the consent token in authorizing shell access. An attacker could exploit this vulnerability by authenticating to the CLI and requesting shell access on an affected device. A successful exploit could allow the attacker to gain shell access on the affected device and execute commands on the underlying OS.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-12671?
CVE-2019-12671 is a vulnerability in the CLI of Cisco IOS XE Software that allows an authenticated local attacker to gain shell access on an affected device and execute commands on the underlying OS.
How severe is CVE-2019-12671?
CVE-2019-12671 has a severity rating of 7.8 out of 10, indicating a high severity.
How can an attacker exploit CVE-2019-12671?
An attacker can exploit CVE-2019-12671 by leveraging insufficient enforcement of the consent token in authorizing shell access on the affected device.
Which software versions are affected by CVE-2019-12671?
Cisco IOS XE versions 16.11.1 and 16.11.1-a are affected by CVE-2019-12671.
How can I protect my device from CVE-2019-12671?
To protect your device from CVE-2019-12671, Cisco recommends updating to a fixed software release as mentioned in the Cisco Security Advisory.