CVE-2019-1748Improper Certificate Validation in Cisco IOS AND IOS XE Software

Severity
7.4HIGHNVD
EPSS
0.3%
top 49.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 28
Latest updateMay 13

Description

A vulnerability in the Cisco Network Plug-and-Play (PnP) agent of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability exists because the affected software insufficiently validates certificates. An attacker could exploit this vulnerability by supplying a crafted certificate to an affected device. A successful exploit could allow the attacker to conduct man-in-the-middle attacks to decrypt and

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 2.2 | Impact: 5.2

Affected Packages3 packages

CVEListV5cisco/cisco_ios_and_ios_xe_software182 versions+181
NVDcisco/ios749 versions+748
NVDcisco/ios_xe181 versions+180

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gvw5-52ph-qgfq: A vulnerability in the Cisco Network Plug-and-Play (PnP) agent of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote2022-05-13
CVEList
Cisco IOS and IOS XE Software Network Plug-and-Play Agent Certificate Validation Vulnerability2019-03-27

📋Vendor Advisories

1
Cisco
Cisco IOS and IOS XE Software Network Plug-and-Play Agent Certificate Validation Vulnerability2019-03-27
CVE-2019-1748 — Improper Certificate Validation | cvebase