← Back

CVE-2019-1757

nvd nist
Published: Mar 28, 2019Modified: Nov 21, 2024

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

A vulnerability in the Cisco Smart Call Home feature of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data using an invalid certificate. The vulnerability is due to insufficient certificate validation by the affected software. An attacker could exploit this vulnerability by supplying a crafted certificate to an affected device. A successful exploit could allow the attacker to conduct man-in-the-middle attacks to decrypt confidential information on user connections to the affected software.

Affected (239)

Products: Cisco: Ios, Ios Xe
2 products
Ios
Ios Xe
Configuration A
239 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 12.2(6)i1
Version 12.4(25e)jap1m
Version 12.4(25e)jap26
Version 12.4(25e)jap2
Version 12.4(25e)jaz1
Version 15.1(2)sg8a
Version 15.1(3)svg3d
Version 15.1(3)svi1b
Version 15.1(3)svm3
Version 15.1(3)svn2
Version 15.1(3)svo1
Version 15.1(3)svo2
Version 15.1(3)svp1
Version 15.1(4)m12c
Version 15.2(2)e4
Version 15.2(2)e5
Version 15.2(2)e5a
Version 15.2(2)e5b
Version 15.2(2)e6
Version 15.2(2)e7
Version 15.2(2)e7b
Version 15.2(2)e8
Version 15.2(3)e4
Version 15.2(3)e5
Version 15.2(3)ea1
Version 15.2(4)e2
Version 15.2(4)e3
Version 15.2(4)e4
Version 15.2(4)e5
Version 15.2(4)e5a
Version 15.2(4)e6
Version 15.2(4)ea8
Version 15.2(4)ea9
Version 15.2(4)jaz1
Version 15.2(4)jn1
Version 15.2(4a)ea5
Version 15.2(4m)e2
Version 15.2(4m)e3
Version 15.2(4n)e2
Version 15.2(4o)e2
Version 15.2(4o)e3
Version 15.2(4p)e1
Version 15.2(4q)e1
Version 15.2(4s)e1
Version 15.2(4s)e2
Version 15.2(5)e1
Version 15.2(5)e2
Version 15.2(5)e2b
Version 15.2(5)e2c
Version 15.2(5)e
Version 15.2(5)ea
Version 15.2(5)ex
Version 15.2(5a)e1
Version 15.2(5a)e
Version 15.2(5b)e
Version 15.2(5c)e
Version 15.2(6)e0a
Version 15.2(6)e0c
Version 15.2(6)e1
Version 15.2(6)e1a
Version 15.2(6)e1s
Version 15.2(6)e
Version 15.3(3)ja1n
Version 15.3(3)jd15
Version 15.3(3)jda15
Version 15.3(3)jf35
Version 15.3(3)ji2
Version 15.3(3)ji
Version 15.3(3)jn1
Version 15.3(3)jn2
Version 15.5(3)s1
Version 15.5(3)s1a
Version 15.5(3)s2
Version 15.5(3)s3
Version 15.5(3)s4
Version 15.5(3)s5
Version 15.5(3)s6
Version 15.5(3)s6a
Version 15.5(3)s6b
Version 15.5(3)s7
Version 15.6(1)s1
Version 15.6(1)s2
Version 15.6(1)s3
Version 15.6(1)s4
Version 15.6(1)s
Version 15.6(1)sn1
Version 15.6(1)sn2
Version 15.6(1)sn3
Version 15.6(1)sn
Version 15.6(1)t0a
Version 15.6(1)t1
Version 15.6(1)t2
Version 15.6(1)t3
Version 15.6(1)t
Version 15.6(2)s1
Version 15.6(2)s2
Version 15.6(2)s3
Version 15.6(2)s4
Version 15.6(2)s
Version 15.6(2)sn
Version 15.6(2)sp1
Version 15.6(2)sp2
Version 15.6(2)sp3
Version 15.6(2)sp3b
Version 15.6(2)sp4
Version 15.6(2)sp
Version 15.6(2)t0a
Version 15.6(2)t1
Version 15.6(2)t2
Version 15.6(2)t3
Version 15.6(2)t
Version 15.6(3)m0a
Version 15.6(3)m1
Version 15.6(3)m1a
Version 15.6(3)m1b
Version 15.6(3)m2
Version 15.6(3)m2a
Version 15.6(3)m3
Version 15.6(3)m3a
Version 15.6(3)m4
Version 15.6(3)m
Version 15.6(3)sn
Version 15.6(4)sn
Version 15.6(5)sn
Version 15.6(6)sn
Version 15.6(7)sn
Version 15.7(3)m0a
Version 15.7(3)m1
Version 15.7(3)m2
Version 15.7(3)m
Version 2.3
Cisco
Version 16.2.1
Version 16.2.2
Version 16.3.1
Version 16.3.1a
Version 16.3.2
Version 16.3.3
Version 16.3.4
Version 16.3.5
Version 16.3.5b
Version 16.3.6
Version 16.4.1
Version 16.4.2
Version 16.4.3
Version 16.5.1
Version 16.5.1a
Version 16.5.1b
Version 16.5.2
Version 16.5.3
Version 16.6.1
Version 16.6.2
Version 16.6.3
Version 16.7.1
Version 16.7.1a
Version 16.7.1b
Version 16.7.2
Version 16.8.1
Version 16.8.1a
Version 16.8.1b
Version 16.8.1c
Version 16.8.1d
Version 16.8.1s
Version 16.8.2
Version 16.9.1b
Version 16.9.1c
Version 16.9.1s
Version 3.10.0ce
Version 3.10.0e
Version 3.10.1ae
Version 3.10.1e
Version 3.10.1se
Version 3.16.1as
Version 3.16.1s
Version 3.16.2as
Version 3.16.2bs
Version 3.16.2s
Version 3.16.3as
Version 3.16.3s
Version 3.16.4as
Version 3.16.4bs
Version 3.16.4cs
Version 3.16.4ds
Version 3.16.4es
Version 3.16.4gs
Version 3.16.4s
Version 3.16.5as
Version 3.16.5bs
Version 3.16.5s
Version 3.16.6bs
Version 3.16.6s
Version 3.16.7as
Version 3.16.7bs
Version 3.16.7s
Version 3.17.0s
Version 3.17.1as
Version 3.17.1s
Version 3.17.3s
Version 3.17.4s
Version 3.18.0as
Version 3.18.0s
Version 3.18.0sp
Version 3.18.1asp
Version 3.18.1bsp
Version 3.18.1csp
Version 3.18.1gsp
Version 3.18.1hsp
Version 3.18.1isp
Version 3.18.1s
Version 3.18.1sp
Version 3.18.2asp
Version 3.18.2s
Version 3.18.2sp
Version 3.18.3asp
Version 3.18.3bsp
Version 3.18.3s
Version 3.18.3sp
Version 3.18.4s
Version 3.18.4sp
Version 3.6.4e
Version 3.6.5ae
Version 3.6.5be
Version 3.6.5e
Version 3.6.6e
Version 3.6.7ae
Version 3.6.7be
Version 3.6.7e
Version 3.6.8e
Version 3.7.4e
Version 3.7.5e
Version 3.8.2e
Version 3.8.3e
Version 3.8.4e
Version 3.8.5ae
Version 3.8.5e
Version 3.8.6e
Version 3.9.0e
Version 3.9.1e
Version 3.9.2be
Version 3.9.2e

References (4)

Source: psirt@cisco.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.