CVE-2019-1842: Cisco IOS XR Software Secure Shell Authentication Vulnerability
A vulnerability in the Secure Shell (SSH) authentication function of Cisco IOS XR Software could allow an authenticated, remote attacker to successfully log in to an affected device using two distinct usernames. The vulnerability is due to a logic error that may occur when certain sequences of actions are processed during an SSH login event on the affected device. An attacker could exploit this vulnerability by initiating an SSH session to the device with a specific sequence that presents the two usernames. A successful exploit could result in logging data misrepresentation, user enumeration, or, in certain circumstances, a command authorization bypass. See the Details section for more information.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-1842?
CVE-2019-1842 is a vulnerability in the Secure Shell (SSH) authentication function of Cisco IOS XR Software.
How does CVE-2019-1842 allow an attacker to log in to an affected device?
CVE-2019-1842 allows an authenticated, remote attacker to successfully log in to an affected device using two distinct usernames.
What is the severity of CVE-2019-1842?
The severity of CVE-2019-1842 is medium with a CVSS score of 5.4.
What is the affected software for CVE-2019-1842?
The affected software for CVE-2019-1842 includes Cisco IOS XR Firmware versions 6.1.2.tools, 6.1.3.tools, 6.2.3.tools, and 6.4.2.tools.
How can I fix CVE-2019-1842?
To fix CVE-2019-1842, apply the necessary patches and updates provided by Cisco.