CyberSec.Space Logo
Back to CVE Browser

CVE-2019-1753

HIGH
8.8
CVSS Severity Score
EPSS Score0.0390%
EPSS Percentile37.70th
PublishedMar 28, 2019
Last ModifiedNov 21, 2024

Vulnerability Description

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote attacker to run privileged Cisco IOS commands by using the web UI. The vulnerability is due to a failure to validate and sanitize input in Web Services Management Agent (WSMA) functions. An attacker could exploit this vulnerability by submitting a malicious payload to the affected device's web UI. A successful exploit could allow the lower-privileged attacker to execute arbitrary commands with higher privileges on the affected device.

Affected Platforms (CPE)

πŸ’»
Cisco

Ios Xe

= 3.2.0ja
πŸ’»
Cisco

Ios Xe

= 3.6.10e
πŸ’»
Cisco

Ios Xe

= 16.6.1
πŸ’»
Cisco

Ios Xe

= 16.6.2
πŸ’»
Cisco

Ios Xe

= 16.6.3
πŸ’»
Cisco

Ios Xe

= 16.7.1
πŸ’»
Cisco

Ios Xe

= 16.7.1a
πŸ’»
Cisco

Ios Xe

= 16.7.1b
πŸ’»
Cisco

Ios Xe

= 16.8.1
πŸ’»
Cisco

Ios Xe

= 16.8.1a
πŸ’»
Cisco

Ios Xe

= 16.8.1b
πŸ’»
Cisco

Ios Xe

= 16.8.1c
πŸ’»
Cisco

Ios Xe

= 16.8.1d
πŸ’»
Cisco

Ios Xe

= 16.8.1e
πŸ’»
Cisco

Ios Xe

= 16.8.1s

References & Advisories

Related Vulnerabilities