cbcvebase.
CVE-2019-12650
published 2019-09-25

CVE-2019-12650: Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands…

PriorityP267high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
28.95%
98.0th percentile
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabilities, see the Details section of this advisory.

Affected

5 ranges
VendorProductVersion rangeFixed in
ciscocisco_ios_xe_software_3.2.11asg>= unspecified < n/an/a
ciscoios
ciscoios_xe
ciscoios_xe
ciscoios_xe

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190925-webui-cmd-injection
  • The vulnerability is exploitable via the Cisco IOS XE Web UI (HTTP server); disabling the HTTP Server feature on internet-facing systems is a key mitigation and detection pivot point.
  • Affected Cisco IOS XE devices implanted via related exploitation chain can be coerced to disclose an 18-character hexadecimal unique implant identifier, useful for scanning/detection.
  • ·CVE-2019-12650 affects multiple vulnerabilities in the Cisco IOS XE Web UI; exploitation requires an authenticated remote attacker.
  • ·The Snort rule 3:50118:2 references CVE-2019-12650 but was also leveraged in the context of CVE-2023-20198 implant activity; the exact mechanism for implant installation on fully patched CVE-2021-1435 systems remains undetermined.
  • ·The implant associated with the broader exploitation chain does not survive a reboot, but attackers may establish persistent access via newly created accounts before rebooting.
  • ·Bug IDs associated with CVE-2019-12650 are CSCvo61821, CSCvp78858, and CSCvp95724.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.6HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco7.6HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.