CVE-2019-1742: Cisco IOS XE Software Information Disclosure Vulnerability
A vulnerability in the web UI of Cisco IOS XE Software could allow an unauthenticated, remote attacker to access sensitive configuration information. The vulnerability is due to improper access control to files within the web UI. An attacker could exploit this vulnerability by sending a malicious request to an affected device. A successful exploit could allow the attacker to gain access to sensitive configuration information.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1742?
CVE-2019-1742 has a medium severity rating due to improper access control in the web UI.
How do I fix CVE-2019-1742?
To fix CVE-2019-1742, you should update your Cisco IOS XE software to the latest patched version.
What type of attack can exploit CVE-2019-1742?
CVE-2019-1742 can be exploited by unauthenticated remote attackers to access sensitive configuration information.
Which Cisco IOS XE versions are affected by CVE-2019-1742?
CVE-2019-1742 affects multiple versions of Cisco IOS XE including 3.2.0ja and 16.3.x through 16.7.x.
Is CVE-2019-1742 easy to exploit?
Yes, CVE-2019-1742 is considered easy to exploit due to inadequate access controls in the web UI.