CVE-2019-1755: Cisco IOS XE Software Command Injection Vulnerability
A vulnerability in the Web Services Management Agent (WSMA) function of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary Cisco IOS commands as a privilege level 15 user. The vulnerability occurs because the affected software improperly sanitizes user-supplied input. An attacker could exploit this vulnerability by submitting crafted HTTP requests to the targeted application. A successful exploit could allow the attacker to execute arbitrary commands on the affected device.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1755?
CVE-2019-1755 has a high severity rating due to its ability to allow an authenticated, remote attacker to execute arbitrary Cisco IOS commands.
How do I fix CVE-2019-1755?
To fix CVE-2019-1755, upgrade to a version of Cisco IOS XE that is not affected by this vulnerability.
What products are affected by CVE-2019-1755?
CVE-2019-1755 affects multiple versions of Cisco IOS XE including versions 3.2.0ja, 3.6.10e, and 16.1.x through 16.8.x.
What type of vulnerability is CVE-2019-1755?
CVE-2019-1755 is a command injection vulnerability occurring in the Web Services Management Agent function of Cisco IOS XE.
Can CVE-2019-1755 lead to unauthorized access?
Yes, CVE-2019-1755 could allow an attacker to execute commands with privilege level 15, potentially leading to unauthorized access.