Cisco Ios Xe Software 3.2.11Asg vulnerabilities

5 known vulnerabilities affecting cisco/cisco_ios_xe_software_3.2.11asg.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2019-12651HIGHCVSS 8.8≥ unspecified, < n/a2019-09-25
CVE-2019-12651 [HIGH] CWE-77 CVE-2019-12651: Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could all Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabilities, see the Details section of this advisory.
cvelistv5nvd
CVE-2019-12650HIGHCVSS 8.8≥ unspecified, < n/a2019-09-25
CVE-2019-12650 [HIGH] CWE-77 CVE-2019-12650: Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could all Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabilities, see the Details section of this advisory.
cvelistv5nvd
CVE-2019-12649MEDIUMCVSS 6.7≥ unspecified, < n/a2019-09-25
CVE-2019-12649 [MEDIUM] CWE-347 CVE-2019-12649: A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authentica A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install and boot a malicious software image or execute unsigned binaries on an affected device. The vulnerability exists because, under certain circumstances, an affected device can be configured to not verify the digital signat
cvelistv5nvd
CVE-2019-12670MEDIUMCVSS 6.7≥ unspecified, < n/a2019-09-25
CVE-2019-12670 [MEDIUM] CWE-284 CVE-2019-12670: A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attac A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker within the IOx Guest Shell to modify the namespace container protections on an affected device. The vulnerability is due to insufficient file permissions. An attacker could exploit this vulnerability by modifying files that they should not have ac
cvelistv5nvd
CVE-2019-12660MEDIUMCVSS 5.5≥ unspecified, < n/a2019-09-25
CVE-2019-12660 [MEDIUM] CWE-668 CVE-2019-12660: A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to write values to the underlying memory of an affected device. The vulnerability is due to improper input validation and authorization of specific commands that a user can execute within the CLI. An attacker could exploit this vulnerability by authentica
cvelistv5nvd