First published: Thu Mar 28 2019(Updated: )
A vulnerability in the authorization subsystem of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote attacker to run privileged Cisco IOS commands by using the web UI. The vulnerability is due to improper validation of user privileges of web UI users. An attacker could exploit this vulnerability by submitting a malicious payload to a specific endpoint in the web UI. A successful exploit could allow the lower-privileged attacker to execute arbitrary commands with higher privileges on the affected device.
Credit: ykramarz@cisco.com ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE | =3.2.0ja | |
Cisco IOS XE | =16.7.1 | |
Cisco IOS XE | =16.7.1a | |
Cisco IOS XE | =16.7.1b | |
Cisco IOS XE | =16.8.1 | |
Cisco IOS XE | =16.8.1a | |
Cisco IOS XE | =16.8.1b | |
Cisco IOS XE | =16.8.1c | |
Cisco IOS XE | =16.8.1d | |
Cisco IOS XE | =16.8.1e | |
Cisco IOS XE | =16.8.1s | |
Cisco IOS XE | =16.8.2 | |
Cisco IOS XE | =16.9.1b | |
Cisco IOS XE | =16.9.1c | |
Cisco IOS XE | =16.9.1d | |
Cisco IOS XE | =16.9.1s | |
=3.2.0ja | ||
=16.7.1 | ||
=16.7.1a | ||
=16.7.1b | ||
=16.8.1 | ||
=16.8.1a | ||
=16.8.1b | ||
=16.8.1c | ||
=16.8.1d | ||
=16.8.1e | ||
=16.8.1s | ||
=16.8.2 | ||
=16.9.1b | ||
=16.9.1c | ||
=16.9.1d | ||
=16.9.1s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-1754 is considered high due to its potential exploitation by authenticated users to execute privileged commands.
To fix CVE-2019-1754, update your Cisco IOS XE software to a version that addresses the vulnerability, as outlined in Cisco's security advisory.
CVE-2019-1754 affects multiple versions of Cisco IOS XE, specifically versions 3.2.0ja and 16.7.x, 16.8.x, and 16.9.x.
Yes, CVE-2019-1754 can be exploited remotely by an authenticated but unprivileged user through the web UI.
The main cause of CVE-2019-1754 is improper validation of user privileges within the Cisco IOS XE web interface.