CVE-2019-12650
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Affected (3)
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 16.6.5 |
| Running on/with | Platform Versions |
|---|---|
Cisco 1100 4p Integrated Services Router | All versions |
Cisco 1100 8p Integrated Services Router | All versions |
Cisco 1101 4p Integrated Services Router | All versions |
Cisco 1109 2p Integrated Services Router | All versions |
Cisco 1109 4p Integrated Services Router | All versions |
Cisco 1111x 8p Integrated Services Router | All versions |
Cisco Asr 1001 X | All versions |
Cisco Asr 1002 Hx | All versions |
Cisco Asr 1006 X | All versions |
Cisco Asr 1009 X | All versions |
Cisco Catalyst 9800 40 | All versions |
Cisco Catalyst 9800 80 | All versions |
Cisco Catalyst 9800 Cl | All versions |
Cisco Catalyst 9800 L | All versions |
Cisco Catalyst 9800 L C | All versions |
Cisco Catalyst 9800 L F | All versions |
Cisco Integrated Services Virtual Router | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 17.1.1 |
| Running on/with | Platform Versions |
|---|---|
Cisco Catalyst 3650 12x48uq | All versions |
Cisco Catalyst 3650 12x48ur | All versions |
Cisco Catalyst 3650 12x48uz | All versions |
Cisco Catalyst 3650 24pd | All versions |
Cisco Catalyst 3650 24pdm | All versions |
Cisco Catalyst 3650 48fq | All versions |
Cisco Catalyst 3650 48fqm | All versions |
Cisco Catalyst 3650 8x24uq | All versions |
Cisco Catalyst 3850 12x48u | All versions |
Cisco Catalyst 3850 24u | All versions |
Cisco Catalyst 3850 24xs | All versions |
Cisco Catalyst 3850 24xu | All versions |
Cisco Catalyst 3850 48u | All versions |
Cisco Catalyst 3850 48xs | All versions |
Cisco Catalyst 3850 Nm 2 40g | All versions |
Cisco Catalyst 3850 Nm 8 10g | All versions |
Cisco Catalyst C9200 24p | All versions |
Cisco Catalyst C9200 24t | All versions |
Cisco Catalyst C9200 48p | All versions |
Cisco Catalyst C9200 48t | All versions |
Cisco Catalyst C9200l 24p 4g | All versions |
Cisco Catalyst C9200l 24p 4x | All versions |
Cisco Catalyst C9200l 24pxg 2y | All versions |
Cisco Catalyst C9200l 24pxg 4x | All versions |
Cisco Catalyst C9200l 24t 4g | All versions |
Cisco Catalyst C9200l 24t 4x | All versions |
Cisco Catalyst C9200l 48p 4g | All versions |
Cisco Catalyst C9200l 48p 4x | All versions |
Cisco Catalyst C9200l 48pxg 2y | All versions |
Cisco Catalyst C9200l 48pxg 4x | All versions |
Cisco Catalyst C9200l 48t 4g | All versions |
Cisco Catalyst C9200l 48t 4x | All versions |
Cisco Catalyst C9300 24p | All versions |
Cisco Catalyst C9300 24s | All versions |
Cisco Catalyst C9300 24t | All versions |
Cisco Catalyst C9300 24u | All versions |
Cisco Catalyst C9300 24ux | All versions |
Cisco Catalyst C9300 48p | All versions |
Cisco Catalyst C9300 48s | All versions |
Cisco Catalyst C9300 48t | All versions |
Cisco Catalyst C9300 48u | All versions |
Cisco Catalyst C9300 48un | All versions |
Cisco Catalyst C9300 48uxm | All versions |
Cisco Catalyst C9300l 24p 4g | All versions |
Cisco Catalyst C9300l 24p 4x | All versions |
Cisco Catalyst C9300l 24t 4g | All versions |
Cisco Catalyst C9300l 24t 4x | All versions |
Cisco Catalyst C9300l 48p 4g | All versions |
Cisco Catalyst C9300l 48p 4x | All versions |
Cisco Catalyst C9300l 48t 4g | All versions |
Cisco Catalyst C9300l 48t 4x | All versions |
Cisco Catalyst C9500 12q | All versions |
Cisco Catalyst C9500 16x | All versions |
Cisco Catalyst C9500 24q | All versions |
Cisco Catalyst C9500 24y4c | All versions |
Cisco Catalyst C9500 32c | All versions |
Cisco Catalyst C9500 32qc | All versions |
Cisco Catalyst C9500 40x | All versions |
Cisco Catalyst C9500 48y4c | All versions |
Cisco Cloud Services Router 1000v | All versions |
Related CWEs
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
References (2)
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.