PT-2020-1386 · Cisco · Cisco Ios Xe+1

Mehmet Önder Key

·

Published

2020-01-08

·

Updated

2020-09-28

·

CVE-2019-16009

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco IOS and Cisco IOS XE Software (affected versions not specified)
Description The issue is related to insufficient CSRF protections for the web UI on affected devices, allowing an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. An attacker could exploit this by persuading a user of the interface to follow a malicious link, potentially allowing the attacker to perform arbitrary actions with the privilege level of the targeted user. If the user has administrative privileges, the attacker could alter the configuration, execute commands, or reload an affected device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the web UI to minimize the risk of exploitation. Avoid using the web UI until the issue is resolved. Restrict access to the vulnerable web UI to minimize the risk of exploitation. Consider disabling the web UI until a patch is available.

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00336
CVE-2019-16009

Affected Products

Cisco Ios
Cisco Ios Xe