CVE-2019-1740Improper Input Validation in Cisco IOS AND Cisco Ios-xe Software

Severity
8.6HIGHNVD
EPSS
0.9%
top 24.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 28
Latest updateMay 13

Description

A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability are due to a parsing issue on DNS packets. An attacker could exploit this vulnerability by sending crafted DNS packets through routers that are running an affected version and have NBAR enabled. A successful exploit could allow the attacker to cause the affected device

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HExploitability: 3.9 | Impact: 4.0

Affected Packages3 packages

NVDcisco/ios91 versions+90
NVDcisco/ios_xe58 versions+57

Patches

🔴Vulnerability Details

2
GHSA
GHSA-454m-cf77-vmj9: A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthentic2022-05-13
CVEList
Cisco IOS and IOS XE Software Network-Based Application Recognition Denial of Service Vulnerabilities2019-03-27

📋Vendor Advisories

1
Cisco
Cisco IOS and IOS XE Software Network-Based Application Recognition Denial of Service Vulnerabilities2019-03-27

💬Community

1
Bugzilla
CVE-2020-1735 ansible: path injection on dest parameter in fetch module2020-02-12
CVE-2019-1740 — Improper Input Validation in Cisco | cvebase