CVE-2019-1753
Summary
| CVE | CVE-2019-1753 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-28 00:29:00 UTC |
| Updated | 2019-10-09 23:47:00 UTC |
| Description | A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote attacker to run privileged Cisco IOS commands by using the web UI. The vulnerability is due to a failure to validate and sanitize input in Web Services Management Agent (WSMA) functions. An attacker could exploit this vulnerability by submitting a malicious payload to the affected device's web UI. A successful exploit could allow the lower-privileged attacker to execute arbitrary commands with higher privileges on the affected device. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Cisco | Ios Xe | 16.6.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.6.2 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.6.3 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.7.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.7.1a | All | All | All |
| Operating System | Cisco | Ios Xe | 16.7.1b | All | All | All |
| Operating System | Cisco | Ios Xe | 16.8.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.8.1a | All | All | All |
| Operating System | Cisco | Ios Xe | 16.8.1b | All | All | All |
| Operating System | Cisco | Ios Xe | 16.8.1c | All | All | All |
| Operating System | Cisco | Ios Xe | 16.8.1d | All | All | All |
| Operating System | Cisco | Ios Xe | 16.8.1e | All | All | All |
| Operating System | Cisco | Ios Xe | 16.8.1s | All | All | All |
| Operating System | Cisco | Ios Xe | 3.2.0ja | All | All | All |
| Operating System | Cisco | Ios Xe | 3.6.10e | All | All | All |
| Operating System | Cisco | Ios Xe | 16.6.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.6.2 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.6.3 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.7.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.7.1a | All | All | All |
| Operating System | Cisco | Ios Xe | 16.7.1b | All | All | All |
| Operating System | Cisco | Ios Xe | 16.8.1 | All | All | All |
| Operating System | Cisco | Ios Xe | 16.8.1a | All | All | All |
| Operating System | Cisco | Ios Xe | 16.8.1b | All | All | All |
| Operating System | Cisco | Ios Xe | 16.8.1c | All | All | All |
| Operating System | Cisco | Ios Xe | 16.8.1d | All | All | All |
| Operating System | Cisco | Ios Xe | 16.8.1e | All | All | All |
| Operating System | Cisco | Ios Xe | 16.8.1s | All | All | All |
| Operating System | Cisco | Ios Xe | 3.2.0ja | All | All | All |
| Operating System | Cisco | Ios Xe | 3.6.10e | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco IOS XE Software Privilege Escalation Vulnerability | CISCO | tools.cisco.com | Patch, Vendor Advisory |
| Cisco IOS XE Software CVE-2019-1753 Remote Privilege Escalation Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.