CVE-2019-1754: Cisco IOS XE Software Privilege Escalation Vulnerability
A vulnerability in the authorization subsystem of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote attacker to run privileged Cisco IOS commands by using the web UI. The vulnerability is due to improper validation of user privileges of web UI users. An attacker could exploit this vulnerability by submitting a malicious payload to a specific endpoint in the web UI. A successful exploit could allow the lower-privileged attacker to execute arbitrary commands with higher privileges on the affected device.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1754?
The severity of CVE-2019-1754 is considered high due to its potential exploitation by authenticated users to execute privileged commands.
How do I fix CVE-2019-1754?
To fix CVE-2019-1754, update your Cisco IOS XE software to a version that addresses the vulnerability, as outlined in Cisco's security advisory.
What types of systems are affected by CVE-2019-1754?
CVE-2019-1754 affects multiple versions of Cisco IOS XE, specifically versions 3.2.0ja and 16.7.x, 16.8.x, and 16.9.x.
Can CVE-2019-1754 be exploited remotely?
Yes, CVE-2019-1754 can be exploited remotely by an authenticated but unprivileged user through the web UI.
What is the main cause of CVE-2019-1754?
The main cause of CVE-2019-1754 is improper validation of user privileges within the Cisco IOS XE web interface.