CVE-2019-1748 — Improper Certificate Validation in Cisco IOS AND IOS XE Software
Severity
7.4HIGHNVD
EPSS
0.3%
top 49.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 28
Latest updateMay 13
Description
A vulnerability in the Cisco Network Plug-and-Play (PnP) agent of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability exists because the affected software insufficiently validates certificates. An attacker could exploit this vulnerability by supplying a crafted certificate to an affected device. A successful exploit could allow the attacker to conduct man-in-the-middle attacks to decrypt and…
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 2.2 | Impact: 5.2
Affected Packages3 packages
Patches
🔴Vulnerability Details
2📋Vendor Advisories
1Cisco▶
Cisco IOS and IOS XE Software Network Plug-and-Play Agent Certificate Validation Vulnerability↗2019-03-27