CVE-2019-12650
published 2019-09-25CVE-2019-12650: Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands…
PriorityP267high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
28.95%
98.0th percentile
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios_xe_software_3.2.11asg | >= unspecified < n/a | n/a |
| cisco | ios | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
Detection & IOCsextracted from sources · hover to see the quote
urlhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190925-webui-cmd-injection↗
- →The vulnerability is exploitable via the Cisco IOS XE Web UI (HTTP server); disabling the HTTP Server feature on internet-facing systems is a key mitigation and detection pivot point. ↗
- →Affected Cisco IOS XE devices implanted via related exploitation chain can be coerced to disclose an 18-character hexadecimal unique implant identifier, useful for scanning/detection. ↗
- ·CVE-2019-12650 affects multiple vulnerabilities in the Cisco IOS XE Web UI; exploitation requires an authenticated remote attacker. ↗
- ·The Snort rule 3:50118:2 references CVE-2019-12650 but was also leveraged in the context of CVE-2023-20198 implant activity; the exact mechanism for implant installation on fully patched CVE-2021-1435 systems remains undetermined. ↗
- ·The implant associated with the broader exploitation chain does not survive a reboot, but attackers may establish persistent access via newly created accounts before rebooting. ↗
- ·Bug IDs associated with CVE-2019-12650 are CSCvo61821, CSCvp78858, and CSCvp95724. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.6HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS XE Software Web UI Command Injection Vulnerabilities
vendor_cisco·2019-09-25·CVSS 7.6
CVE-2019-12650 [HIGH] CWE-77 Cisco IOS XE Software Web UI Command Injection Vulnerabilities
Cisco IOS XE Software Web UI Command Injection Vulnerabilities
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190925-webui-cmd-injection
This advisory is part of the September 25, 2019, release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication, which
Cisco
Cisco IOS XE Software Web UI Command Injection Vulnerabilities
vendor_cisco·CVSS 3.0
CVE-2019-12650 Cisco IOS XE Software Web UI Command Injection Vulnerabilities
CVE-2019-12650: Cisco IOS XE Software Web UI Command Injection Vulnerabilities
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabilities, see the
CVSS: 3.0
CWE: CWE-77, CWE-77
Bug IDs: CSCvo61821, CSCvp78858, CSCvp95724
GHSA
GHSA-w77v-9mp2-fhr5: Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute co
ghsa_unreviewed·2022-05-24
CVE-2019-12650 [HIGH] CWE-77 GHSA-w77v-9mp2-fhr5: Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute co
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabilities, see the Details section of this advisory.
No detection rules found.
No public exploits indexed.
Greynoiseio
NoiseLetter March 2026
blogs_greynoiseio
NoiseLetter March 2026
Events, events… and yes, even more events. 🌍 GreyNoise has been on the move. March kept us busy with stops at eCrimes in London and SecIT in Hanover—but we’re just getting started. Over the next few months, we’ll be hitting the road for CrowdStrike CrowdTours across eight cities, heading to Glasgow to speak and sponsor CyberUK, and making our way to Tampa for H-ISAC. If you’ll be at any of these (or nearby), we’d love to connect.
And while we’ve been racking up miles, we haven’t slowed down on the research front. We’ve just released some exciting new findings—with even more coming in the next few weeks—so keep an eye out.
Thanks, as always, for being part of the GreyNoise community.
Featured
About this new report
Every enterprise firewall processes traffic from residential IP space. T
Greynoiseio
Unpacking CVE-2023-20198: A Critical Weakness In Cisco IOS XE:
blogs_greynoiseio·CVSS 10.0
[CRITICAL] Unpacking CVE-2023-20198: A Critical Weakness In Cisco IOS XE:
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
2019-09-25
Published