← Back

CVE-2019-12648

nvd nist
Published: Sep 25, 2019Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

A vulnerability in the IOx application environment for Cisco IOS Software could allow an authenticated, remote attacker to gain unauthorized access to the Guest Operating System (Guest OS) running on an affected device. The vulnerability is due to incorrect role-based access control (RBAC) evaluation when a low-privileged user requests access to a Guest OS that should be restricted to administrative accounts. An attacker could exploit this vulnerability by authenticating to the Guest OS by using the low-privileged-user credentials. An exploit could allow the attacker to gain unauthorized access to the Guest OS as a root user.

Affected (1)

Products: Cisco: Ios
1 product
Ios
Configuration A
1 vulnerable · 5 platform
Vulnerable SoftwareAffected Versions
Version 15.7(3)m3
Running on/withPlatform Versions
Cisco
807 Industrial Integrated Services Routers
All versions
Cisco
809 Industrial Integrated Services Routers
All versions
Cisco
829 Industrial Integrated Services Routers
All versions
Cisco
Cgr1240
All versions
Cisco
Cgr 1120
All versions

Timeline

No history available yet.