PT-2019-1748 · Cisco · Cisco Ios Xe

Published

2019-03-27

·

Updated

2020-10-09

·

CVE-2019-1759

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco IOS XE Software versions 16.1.1 and later
Description A logic error in the access control list (ACL) functionality of the Gigabit Ethernet Management interface could allow an unauthenticated, remote attacker to reach the configured IP addresses on the interface. This issue prevents the ACL from working when applied against the management interface, potentially allowing an attacker to access the device via the management interface.
Recommendations For Cisco IOS XE Software version 16.1.1 and later, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the management interface to minimize the risk of exploitation. Additionally, applying partial workarounds may help address this issue until a full update can be applied.

Fix

Improper Access Control

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01387
CVE-2019-1759

Affected Products

Cisco Ios Xe