CVE-2019-1752Improper Input Validation in Cisco IOS AND IOS XE Software

Severity
7.5HIGHNVD
EPSS
1.3%
top 19.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 28
Latest updateMay 13

Description

A vulnerability in the ISDN functions of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload. The vulnerability is due to incorrect processing of specific values in the Q.931 information elements. An attacker could exploit this vulnerability by calling the affected device with specific Q.931 information elements being present. An exploit could allow the attacker to cause the device to reload, resulting in a denial of service

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

CVEListV5cisco/cisco_ios_and_ios_xe_software130 versions+129
NVDcisco/ios193 versions+192
NVDcisco/ios_xe129 versions+128

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2mf8-3wf7-hj2g: A vulnerability in the ISDN functions of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the dev2022-05-13
CVEList
Cisco IOS and IOS XE Software ISDN Interface Denial of Service Vulnerability2019-03-28

📋Vendor Advisories

1
Cisco
Cisco IOS and IOS XE Software ISDN Interface Denial of Service Vulnerability2019-03-27
CVE-2019-1752 — Improper Input Validation in Cisco | cvebase