CVE-2019-1757Improper Certificate Validation in Cisco IOS AND IOS XE Software

Severity
5.9MEDIUMNVD
EPSS
0.3%
top 44.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 28
Latest updateMay 13

Description

A vulnerability in the Cisco Smart Call Home feature of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data using an invalid certificate. The vulnerability is due to insufficient certificate validation by the affected software. An attacker could exploit this vulnerability by supplying a crafted certificate to an affected device. A successful exploit could allow the attacker to conduct man-in-the-middle attacks to decryp

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages3 packages

CVEListV5cisco/cisco_ios_and_ios_xe_software109 versions+108
NVDcisco/ios131 versions+130
NVDcisco/ios_xe108 versions+107

🔴Vulnerability Details

2
GHSA
GHSA-pqr7-9qqq-hrh5: A vulnerability in the Cisco Smart Call Home feature of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to gain unauthor2022-05-13
CVEList
Cisco IOS and IOS XE Software Smart Call Home Certificate Validation Vulnerability2019-03-28

📋Vendor Advisories

1
Cisco
Cisco IOS and IOS XE Software Smart Call Home Certificate Validation Vulnerability2019-03-27
CVE-2019-1757 — Improper Certificate Validation | cvebase