CVE-2019-1748

HIGHCVSS 7.4/10EPSS 1.18%

Last modified

CVE-2019-1748 is a high-severity vulnerability rated 7.4/10 on the CVSS scale. A vulnerability in the Cisco Network Plug-and-Play (PnP) agent of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability exists because the affected software insufficiently validates certificates. EPSS estimates a 1.18% chance of exploitation in the next 30 days.

Description

A vulnerability in the Cisco Network Plug-and-Play (PnP) agent of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability exists because the affected software insufficiently validates certificates. An attacker could exploit this vulnerability by supplying a crafted certificate to an affected device. A successful exploit could allow the attacker to conduct man-in-the-middle attacks to decrypt and modify confidential information on user connections to the affected software.

Metrics

CVSS 3.1
7.4/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

EPSS Probability
1.18%

63.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
CiscoIos12.0\(1\)
CiscoIos12.0\(1\)t
CiscoIos12.0\(1\)t1
CiscoIos12.0\(1\)xe
CiscoIos12.0\(1a\)
CiscoIos12.0\(2\)
CiscoIos12.0\(2\)s
CiscoIos12.0\(2\)t
CiscoIos12.0\(2\)t1
CiscoIos12.0\(2\)xe
CiscoIos12.0\(2\)xe1
CiscoIos12.0\(2\)xe3
CiscoIos12.0\(2\)xe4
CiscoIos12.0\(2a\)
CiscoIos12.0\(2a\)t1
CiscoIos12.0\(2b\)
CiscoIos12.0\(3\)
CiscoIos12.0\(3\)s
CiscoIos12.0\(3\)t
CiscoIos12.0\(3\)t2
CiscoIos12.0\(3\)t3
CiscoIos12.0\(3a\)
CiscoIos12.0\(3b\)
CiscoIos12.0\(3c\)
CiscoIos12.0\(3d\)
CiscoIos12.0\(4\)
CiscoIos12.0\(4\)s
CiscoIos12.0\(4\)t
CiscoIos12.0\(4\)xe
CiscoIos12.0\(4\)xe2
CiscoIos12.0\(4a\)
CiscoIos12.0\(4b\)
CiscoIos12.0\(5\)
CiscoIos12.0\(5\)s
CiscoIos12.0\(5\)t
CiscoIos12.0\(5\)t1
CiscoIos12.0\(5\)xe
CiscoIos12.0\(5\)xe1
CiscoIos12.0\(5\)xe2
CiscoIos12.0\(5\)xe3
CiscoIos12.0\(5\)xe4
CiscoIos12.0\(5\)xe5
CiscoIos12.0\(5\)xe8
CiscoIos12.0\(5\)xt1
CiscoIos12.0\(5a\)
CiscoIos12.0\(6\)
CiscoIos12.0\(6\)s
CiscoIos12.0\(6\)s1
CiscoIos12.0\(6\)s2
CiscoIos12.0\(6a\)

Showing 50 of 930 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-1748?
A vulnerability in the Cisco Network Plug-and-Play (PnP) agent of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability exists because the affected software insufficiently validates certificates. An attacker could exploit this vulnerability by supplying a crafted certificate to an affected device. A successful exploit could allow the attacker to conduct man-in-the-middle attacks to decrypt and modify confidential information on user connections to the affected software.
How severe is CVE-2019-1748?
CVE-2019-1748 has a CVSS score of 7.4/10 (HIGH severity). The EPSS model estimates a 1.18% probability of exploitation in the next 30 days.
How do I fix CVE-2019-1748?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-1748?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST