PT-2019-1748 · Cisco · Cisco Ios Xe
Published
2019-03-27
·
Updated
2020-10-09
·
CVE-2019-1759
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XE Software versions 16.1.1 and later
Description
A logic error in the access control list (ACL) functionality of the Gigabit Ethernet Management interface could allow an unauthenticated, remote attacker to reach the configured IP addresses on the interface. This issue prevents the ACL from working when applied against the management interface, potentially allowing an attacker to access the device via the management interface.
Recommendations
For Cisco IOS XE Software version 16.1.1 and later, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the management interface to minimize the risk of exploitation. Additionally, applying partial workarounds may help address this issue until a full update can be applied.
Fix
Improper Access Control
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Ios Xe