Description
A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, local attacker to gain unauthorized access to an affected device. The vulnerability is due to the existence of default credentials within the default configuration of an affected device. An attacker who has access to an affected device could log in with elevated privileges. A successful exploit could allow the attacker to take complete control of the device. This vulnerability affects Cisco devices that are running Cisco IOS XE SD-WAN Software releases 16.11 and earlier.
Published: 2020-02-19
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Cisco fixed this vulnerability in Cisco IOS XE SD-WAN Software Release 16.12.1.


Vendor Workaround

To check for the presence of default credentials, customers can use the show running-configuration | include username admin command within the Cisco IOS XE SD-WAN Software command line. To remove the default credentials, customers can use the config-transaction and no username admin commands.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-10507 A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, local attacker to gain unauthorized access to an affected device. The vulnerability is due to the existence of default credentials within the default configuration of an affected device. An attacker who has access to an affected device could log in with elevated privileges. A successful exploit could allow the attacker to take complete control of the device. This vulnerability affects Cisco devices that are running Cisco IOS XE SD-WAN Software releases 16.11 and earlier.
History

Tue, 24 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Cisco 1100-4p Integrated Services Router 1100-8p Integrated Services Router 1101-4p Integrated Services Router 1109-2p Integrated Services Router 1109-4p Integrated Services Router 1111x-8p Integrated Services Router 4221 Integrated Services Router 4331 Integrated Services Router 4431 Integrated Services Router 4461 Integrated Services Router Asr 1000-x Asr 1001-hx Asr 1002-hx Asr 1002-x Asr 1004 Asr 1006 Asr 1006-x Asr 1009-x Asr 1013 Csr1000v Ios Xe Ir1101 Nexus 56128p Nexus 5624q Nexus 5648q Nexus 5672up Nexus 5672up-16g Nexus 5696q Ucs-e1120d-m3 Ucs-e140s-m2 Ucs-e160d-m2 Ucs-e160s-m3 Ucs-e180d-m2 Ucs-e180d-m3
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-15T17:39:14.041Z

Reserved: 2018-12-06T00:00:00.000Z

Link: CVE-2019-1950

cve-icon Vulnrichment

Updated: 2024-08-04T18:35:51.831Z

cve-icon NVD

Status : Modified

Published: 2020-02-19T20:15:14.410

Modified: 2024-11-21T04:37:45.133

Link: CVE-2019-1950

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses