CVE-2019-1950
Summary
| CVE | CVE-2019-1950 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-19 20:15:00 UTC |
| Updated | 2023-05-22 18:57:00 UTC |
| Description | A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, local attacker to gain unauthorized access to an affected device. The vulnerability is due to the existence of default credentials within the default configuration of an affected device. An attacker who has access to an affected device could log in with elevated privileges. A successful exploit could allow the attacker to take complete control of the device. This vulnerability affects Cisco devices that are running Cisco IOS XE SD-WAN Software releases 16.11 and earlier. |
Risk And Classification
Problem Types: CWE-1188
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | 1100-4p Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 1100-8p Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 1101-4p Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 1109-2p Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 1109-4p Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 1111x-8p Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 4221 Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 4331 Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 4431 Integrated Services Router | - | All | All | All |
| Hardware | Cisco | 4461 Integrated Services Router | - | All | All | All |
| Hardware | Cisco | Asr 1000-x | - | All | All | All |
| Hardware | Cisco | Asr 1000-x | - | All | All | All |
| Hardware | Cisco | Asr 1001-hx | - | All | All | All |
| Hardware | Cisco | Asr 1001-hx | - | All | All | All |
| Hardware | Cisco | Asr 1002-hx | - | All | All | All |
| Hardware | Cisco | Asr 1002-hx | - | All | All | All |
| Hardware | Cisco | Asr 1002-x | - | All | All | All |
| Hardware | Cisco | Asr 1002-x | - | All | All | All |
| Hardware | Cisco | Asr 1004 | - | All | All | All |
| Hardware | Cisco | Asr 1004 | - | All | All | All |
| Hardware | Cisco | Asr 1006 | - | All | All | All |
| Hardware | Cisco | Asr 1006 | - | All | All | All |
| Hardware | Cisco | Asr 1006-x | - | All | All | All |
| Hardware | Cisco | Asr 1006-x | - | All | All | All |
| Hardware | Cisco | Asr 1009-x | - | All | All | All |
| Hardware | Cisco | Asr 1009-x | - | All | All | All |
| Hardware | Cisco | Asr 1013 | - | All | All | All |
| Hardware | Cisco | Asr 1013 | - | All | All | All |
| Hardware | Cisco | Csr1000v | - | All | All | All |
| Hardware | Cisco | Csr1000v | - | All | All | All |
| Operating System | Cisco | Ios Xe | All | All | All | All |
| Hardware | Cisco | Ir1101 | - | All | All | All |
| Hardware | Cisco | Ir1101 | - | All | All | All |
| Hardware | Cisco | Isr 1100-4p | - | All | All | All |
| Hardware | Cisco | Isr 1100-4p | - | All | All | All |
| Hardware | Cisco | Isr 1100-8p | - | All | All | All |
| Hardware | Cisco | Isr 1100-8p | - | All | All | All |
| Hardware | Cisco | Isr 1101-4p | - | All | All | All |
| Hardware | Cisco | Isr 1101-4p | - | All | All | All |
| Hardware | Cisco | Isr 1109-2p | - | All | All | All |
| Hardware | Cisco | Isr 1109-2p | - | All | All | All |
| Hardware | Cisco | Isr 1109-4p | - | All | All | All |
| Hardware | Cisco | Isr 1109-4p | - | All | All | All |
| Hardware | Cisco | Isr 1111x-8p | - | All | All | All |
| Hardware | Cisco | Isr 1111x-8p | - | All | All | All |
| Hardware | Cisco | Isr 4221 | - | All | All | All |
| Hardware | Cisco | Isr 4221 | - | All | All | All |
| Hardware | Cisco | Isr 4331 | - | All | All | All |
| Hardware | Cisco | Isr 4331 | - | All | All | All |
| Hardware | Cisco | Isr 4431 | - | All | All | All |
| Hardware | Cisco | Isr 4431 | - | All | All | All |
| Hardware | Cisco | Isr 4461 | - | All | All | All |
| Hardware | Cisco | Isr 4461 | - | All | All | All |
| Hardware | Cisco | Nexus 56128p | - | All | All | All |
| Hardware | Cisco | Nexus 56128p | - | All | All | All |
| Hardware | Cisco | Nexus 5624q | - | All | All | All |
| Hardware | Cisco | Nexus 5624q | - | All | All | All |
| Hardware | Cisco | Nexus 5648q | - | All | All | All |
| Hardware | Cisco | Nexus 5648q | - | All | All | All |
| Hardware | Cisco | Nexus 5672up | - | All | All | All |
| Hardware | Cisco | Nexus 5672up | - | All | All | All |
| Hardware | Cisco | Nexus 5672up-16g | - | All | All | All |
| Hardware | Cisco | Nexus 5672up-16g | - | All | All | All |
| Hardware | Cisco | Nexus 5696q | - | All | All | All |
| Hardware | Cisco | Nexus 5696q | - | All | All | All |
| Hardware | Cisco | Ucs-e1120d-m3 | - | All | All | All |
| Hardware | Cisco | Ucs-e1120d-m3 | - | All | All | All |
| Hardware | Cisco | Ucs-e140s-m2 | - | All | All | All |
| Hardware | Cisco | Ucs-e140s-m2 | - | All | All | All |
| Hardware | Cisco | Ucs-e160d-m2 | - | All | All | All |
| Hardware | Cisco | Ucs-e160d-m2 | - | All | All | All |
| Hardware | Cisco | Ucs-e160s-m3 | - | All | All | All |
| Hardware | Cisco | Ucs-e160s-m3 | - | All | All | All |
| Hardware | Cisco | Ucs-e180d-m2 | - | All | All | All |
| Hardware | Cisco | Ucs-e180d-m2 | - | All | All | All |
| Hardware | Cisco | Ucs-e180d-m3 | - | All | All | All |
| Hardware | Cisco | Ucs-e180d-m3 | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco IOS XE SD-WAN Software Default Credentials Vulnerability | CONFIRM | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.