CVE-2019-1746
Last modified
CVE-2019-1746 is a vulnerability of currently unknown severity. A vulnerability in the Cluster Management Protocol (CMP) processing code in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation when processing CMP management packets. EPSS estimates a 0.64% chance of exploitation in the next 30 days.
Description
A vulnerability in the Cluster Management Protocol (CMP) processing code in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation when processing CMP management packets. An attacker could exploit this vulnerability by sending malicious CMP management packets to an affected device. A successful exploit could cause the switch to crash, resulting in a DoS condition. The switch will reload automatically.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios | 12.1\(6\)ea1 |
| Cisco | Ios | 12.1\(6\)ea1a |
| Cisco | Ios | 12.1\(6\)ea2 |
| Cisco | Ios | 12.1\(6\)ea2a |
| Cisco | Ios | 12.1\(6\)ea2b |
| Cisco | Ios | 12.1\(6\)ea2c |
| Cisco | Ios | 12.1\(8\)ea1b |
| Cisco | Ios | 12.1\(8\)ea1c |
| Cisco | Ios | 12.1\(9\)ea1 |
| Cisco | Ios | 12.1\(9\)ea1a |
| Cisco | Ios | 12.1\(9\)ea1c |
| Cisco | Ios | 12.1\(9\)ea1d |
| Cisco | Ios | 12.1\(9\)ex |
| Cisco | Ios | 12.1\(11\)ea1 |
| Cisco | Ios | 12.1\(11\)ea1a |
| Cisco | Ios | 12.1\(12c\)ea1 |
| Cisco | Ios | 12.1\(12c\)ea1a |
| Cisco | Ios | 12.1\(13\)ea1 |
| Cisco | Ios | 12.1\(13\)ea1a |
| Cisco | Ios | 12.1\(13\)ea1b |
| Cisco | Ios | 12.1\(13\)ea1c |
| Cisco | Ios | 12.1\(14\)az |
| Cisco | Ios | 12.1\(14\)ea1 |
| Cisco | Ios | 12.1\(14\)ea1a |
| Cisco | Ios | 12.1\(14\)ea1b |
| Cisco | Ios | 12.1\(19\)ea1 |
| Cisco | Ios | 12.1\(19\)ea1a |
| Cisco | Ios | 12.1\(19\)ea1b |
| Cisco | Ios | 12.1\(19\)ea1c |
| Cisco | Ios | 12.1\(19\)ea1d |
| Cisco | Ios | 12.1\(20\)ea1 |
| Cisco | Ios | 12.1\(20\)ea1a |
| Cisco | Ios | 12.1\(20\)ea1b |
| Cisco | Ios | 12.1\(20\)ea2 |
| Cisco | Ios | 12.1\(22\)ea1 |
| Cisco | Ios | 12.1\(22\)ea1a |
| Cisco | Ios | 12.1\(22\)ea1b |
| Cisco | Ios | 12.1\(22\)ea2 |
| Cisco | Ios | 12.1\(22\)ea3 |
| Cisco | Ios | 12.1\(22\)ea4 |
| Cisco | Ios | 12.1\(22\)ea4a |
| Cisco | Ios | 12.1\(22\)ea5 |
| Cisco | Ios | 12.1\(22\)ea5a |
| Cisco | Ios | 12.1\(22\)ea6 |
| Cisco | Ios | 12.1\(22\)ea6a |
| Cisco | Ios | 12.1\(22\)ea7 |
| Cisco | Ios | 12.1\(22\)ea8 |
| Cisco | Ios | 12.1\(22\)ea8a |
| Cisco | Ios | 12.1\(22\)ea9 |
| Cisco | Ios | 12.1\(22\)ea10 |
Showing 50 of 567 affected configurations. See NVD for the full list.
References
- http://www.securityfocus.com/bid/107612Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/107612Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-1746?
How severe is CVE-2019-1746?
How do I fix CVE-2019-1746?
Are you affected by CVE-2019-1746?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
