CVE-2019-12651
published 2019-09-25CVE-2019-12651: Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands…
PriorityP356high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.54%
83.3th percentile
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios_xe_software_3.2.11asg | >= unspecified < n/a | n/a |
| cisco | cloud_services_router_1000v_firmware | — | — |
| cisco | integrated_services_virtual_router_firmware | — | — |
| cisco | ios | — | — |
| cisco | ios_xe | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability class is command injection (CWE-77) in the Cisco IOS XE Web UI; monitor for authenticated HTTP/HTTPS requests to the Web UI that contain shell metacharacters or unexpected command syntax in parameters ↗
- →Track Cisco bug IDs CSCvo61821, CSCvp78858, and CSCvp95724 for patch status and additional technical details that may surface exploitable endpoints ↗
- ·Exploitation requires the attacker to be authenticated; ensure Web UI access is restricted to trusted management networks and that strong authentication controls are enforced ↗
- ·No workarounds are available; the only mitigation is applying the vendor-supplied software update ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.6HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS XE Software Web UI Command Injection Vulnerabilities
vendor_cisco·2019-09-25·CVSS 7.6
CVE-2019-12650 [HIGH] CWE-77 Cisco IOS XE Software Web UI Command Injection Vulnerabilities
Cisco IOS XE Software Web UI Command Injection Vulnerabilities
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190925-webui-cmd-injection
This advisory is part of the September 25, 2019, release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication, which
Cisco
Cisco IOS XE Software Web UI Command Injection Vulnerabilities
vendor_cisco·CVSS 3.0
CVE-2019-12651 Cisco IOS XE Software Web UI Command Injection Vulnerabilities
CVE-2019-12651: Cisco IOS XE Software Web UI Command Injection Vulnerabilities
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabilities, see the
CVSS: 3.0
CWE: CWE-77, CWE-77
Bug IDs: CSCvo61821, CSCvp78858, CSCvp95724
GHSA
GHSA-375x-49qp-94gv: Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute co
ghsa_unreviewed·2022-05-24
CVE-2019-12651 [HIGH] CWE-77 GHSA-375x-49qp-94gv: Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute co
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabilities, see the Details section of this advisory.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-09-25
Published