CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2019-1753

HIGH
8.8
CVSS Severity Score
EPSS Score0.0390%
EPSS Percentile37.70th
Published2019年3月28日
Last Modified2024年11月21日

Vulnerability Description

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote attacker to run privileged Cisco IOS commands by using the web UI. The vulnerability is due to a failure to validate and sanitize input in Web Services Management Agent (WSMA) functions. An attacker could exploit this vulnerability by submitting a malicious payload to the affected device's web UI. A successful exploit could allow the lower-privileged attacker to execute arbitrary commands with higher privileges on the affected device.

Affected Platforms (CPE)

💻
Cisco

Ios Xe

= 3.2.0ja
💻
Cisco

Ios Xe

= 3.6.10e
💻
Cisco

Ios Xe

= 16.6.1
💻
Cisco

Ios Xe

= 16.6.2
💻
Cisco

Ios Xe

= 16.6.3
💻
Cisco

Ios Xe

= 16.7.1
💻
Cisco

Ios Xe

= 16.7.1a
💻
Cisco

Ios Xe

= 16.7.1b
💻
Cisco

Ios Xe

= 16.8.1
💻
Cisco

Ios Xe

= 16.8.1a
💻
Cisco

Ios Xe

= 16.8.1b
💻
Cisco

Ios Xe

= 16.8.1c
💻
Cisco

Ios Xe

= 16.8.1d
💻
Cisco

Ios Xe

= 16.8.1e
💻
Cisco

Ios Xe

= 16.8.1s

References & Advisories

相關漏洞威脅