A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execute commands on the underlying operating system (OS). The vulnerability is due to insufficient enforcement of the consent token in authorizing shell access. An attacker could exploit this vulnerability by authenticating to the CLI and requesting shell access on an affected device. A successful exploit could allow the attacker to gain shell access on the affected device and execute commands on the underlying OS.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
4321\/k9-rf Integrated Services Router
Subscribe
4321\/k9-ws Integrated Services Router
Subscribe
4321\/k9 Integrated Services Router
Subscribe
4331\/k9-rf Integrated Services Router
Subscribe
4331\/k9-ws Integrated Services Router
Subscribe
4331\/k9 Integrated Services Router
Subscribe
4351\/k9-rf Integrated Services Router
Subscribe
4351\/k9-ws Integrated Services Router
Subscribe
4351\/k9 Integrated Services Router
Subscribe
Asr1001-hx
Subscribe
Asr1001-hx-rf
Subscribe
Asr1001-x
Subscribe
Asr1001-x-rf
Subscribe
Asr1001-x-ws
Subscribe
Asr1002-hx
Subscribe
Asr1002-hx-rf
Subscribe
Asr1002-hx-ws
Subscribe
Asr1002-x
Subscribe
Asr1002-x-rf
Subscribe
Asr1002-x-ws
Subscribe
C1117-4p
Subscribe
C1117-4plteea
Subscribe
C1117-4pltela
Subscribe
Encs5412\/k9
Subscribe
Encs5412\/k9-rf
Subscribe
Ios Xe
Subscribe
Sasr1k1xucmk9-1610
Subscribe
Sasr1k2xucmk9-1610
Subscribe
Sasr1khxucmk9-1610
Subscribe
Sisr1100ucmk9-1610
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-4262 | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execute commands on the underlying operating system (OS). The vulnerability is due to insufficient enforcement of the consent token in authorizing shell access. An attacker could exploit this vulnerability by authenticating to the CLI and requesting shell access on an affected device. A successful exploit could allow the attacker to gain shell access on the affected device and execute commands on the underlying OS. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 20 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-20T17:10:08.306Z
Reserved: 2019-06-04T00:00:00
Link: CVE-2019-12671
Updated: 2024-08-04T23:24:39.172Z
Status : Modified
Published: 2019-09-25T21:15:11.750
Modified: 2024-11-21T04:23:19.470
Link: CVE-2019-12671
No data.
OpenCVE Enrichment
No data.
EUVD