CVE-2019-1743
Cisco IOS XE Software Arbitrary File Upload Vulnerability
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.8EPSS 2.2%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
27 mar 2019Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A vulnerability in the web UI framework of Cisco IOS XE Software could allow an authenticated, remote attacker to make unauthorized changes to the filesystem of the affected device. The vulnerability is due to improper input validation. An attacker could exploit this vulnerability by crafting a malicious file and uploading it to the device. An exploit could allow the attacker to gain elevated privileges on the affected device.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Cisco · Cisco IOS XE Software¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →