← Back

CVE-2019-1745

nvd nist
Published: Mar 28, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with elevated privileges. The vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted input to the affected commands. An exploit could allow the attacker to gain root privileges on the affected device.

Affected (155)

Products: Cisco: Ios Xe
1 product
Ios Xe
Configuration A
155 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 16.1.1
Version 16.1.2
Version 16.1.3
Version 16.2.1
Version 16.2.2
Version 16.3.1
Version 16.3.1a
Version 16.3.2
Version 16.3.3
Version 16.3.4
Version 16.3.5
Version 16.3.5b
Version 16.3.6
Version 16.3.7
Version 16.4.1
Version 16.4.2
Version 16.4.3
Version 16.5.1
Version 16.5.1a
Version 16.5.1b
Version 16.5.2
Version 16.5.3
Version 16.6.1
Version 16.6.2
Version 16.6.3
Version 16.6.4
Version 16.6.4a
Version 16.6.4s
Version 16.7.1
Version 16.7.1a
Version 16.7.1b
Version 16.7.2
Version 16.8.1
Version 16.8.1a
Version 16.8.1b
Version 16.8.1c
Version 16.8.1d
Version 16.8.1e
Version 16.8.1s
Version 16.8.2
Version 16.9.1
Version 16.9.1a
Version 16.9.1b
Version 16.9.1c
Version 16.9.1d
Version 16.9.1s
Version 16.9.2
Version 16.9.2a
Version 3.10.0s
Version 3.10.10s
Version 3.10.1s
Version 3.10.2as
Version 3.10.2s
Version 3.10.2ts
Version 3.10.3s
Version 3.10.4s
Version 3.10.5s
Version 3.10.6s
Version 3.10.7s
Version 3.10.8as
Version 3.10.8s
Version 3.10.9s
Version 3.11.0s
Version 3.11.1s
Version 3.11.2s
Version 3.11.3s
Version 3.11.4s
Version 3.12.0as
Version 3.12.0s
Version 3.12.1s
Version 3.12.2s
Version 3.12.3s
Version 3.12.4s
Version 3.13.0as
Version 3.13.0s
Version 3.13.10s
Version 3.13.1s
Version 3.13.2as
Version 3.13.2s
Version 3.13.3s
Version 3.13.4s
Version 3.13.5as
Version 3.13.5s
Version 3.13.6as
Version 3.13.6bs
Version 3.13.6s
Version 3.13.7as
Version 3.13.7s
Version 3.13.8s
Version 3.13.9s
Version 3.14.0s
Version 3.14.1s
Version 3.14.2s
Version 3.14.3s
Version 3.14.4s
Version 3.15.0s
Version 3.15.1cs
Version 3.15.1s
Version 3.15.2s
Version 3.15.3s
Version 3.15.4s
Version 3.16.0as
Version 3.16.0bs
Version 3.16.0cs
Version 3.16.0s
Version 3.16.1as
Version 3.16.1s
Version 3.16.2as
Version 3.16.2bs
Version 3.16.2s
Version 3.16.3as
Version 3.16.3s
Version 3.16.4as
Version 3.16.4bs
Version 3.16.4cs
Version 3.16.4ds
Version 3.16.4es
Version 3.16.4gs
Version 3.16.4s
Version 3.16.5as
Version 3.16.5bs
Version 3.16.5s
Version 3.16.6bs
Version 3.16.6s
Version 3.16.7as
Version 3.16.7bs
Version 3.16.7s
Version 3.16.8s
Version 3.17.0s
Version 3.17.1as
Version 3.17.1s
Version 3.17.3s
Version 3.17.4s
Version 3.18.0as
Version 3.18.0s
Version 3.18.0sp
Version 3.18.1asp
Version 3.18.1bsp
Version 3.18.1csp
Version 3.18.1gsp
Version 3.18.1hsp
Version 3.18.1isp
Version 3.18.1s
Version 3.18.1sp
Version 3.18.2asp
Version 3.18.2s
Version 3.18.2sp
Version 3.18.3asp
Version 3.18.3bsp
Version 3.18.3s
Version 3.18.3sp
Version 3.18.4s
Version 3.18.4sp
Version 3.18.5sp
Version 3.6.10e

References (4)

Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.