CVE-2019-1755
Last modified
CVE-2019-1755 is a vulnerability of currently unknown severity. A vulnerability in the Web Services Management Agent (WSMA) function of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary Cisco IOS commands as a privilege level 15 user. The vulnerability occurs because the affected software improperly sanitizes user-supplied input. EPSS estimates a 3.45% chance of exploitation in the next 30 days.
Description
A vulnerability in the Web Services Management Agent (WSMA) function of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary Cisco IOS commands as a privilege level 15 user. The vulnerability occurs because the affected software improperly sanitizes user-supplied input. An attacker could exploit this vulnerability by submitting crafted HTTP requests to the targeted application. A successful exploit could allow the attacker to execute arbitrary commands on the affected device.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xe | 3.2.0ja |
| Cisco | Ios Xe | 3.6.10e |
| Cisco | Ios Xe | 16.1.1 |
| Cisco | Ios Xe | 16.1.2 |
| Cisco | Ios Xe | 16.1.3 |
| Cisco | Ios Xe | 16.2.1 |
| Cisco | Ios Xe | 16.2.2 |
| Cisco | Ios Xe | 16.3.1 |
| Cisco | Ios Xe | 16.3.1a |
| Cisco | Ios Xe | 16.3.2 |
| Cisco | Ios Xe | 16.3.3 |
| Cisco | Ios Xe | 16.3.4 |
| Cisco | Ios Xe | 16.3.5 |
| Cisco | Ios Xe | 16.3.5b |
| Cisco | Ios Xe | 16.3.6 |
| Cisco | Ios Xe | 16.3.7 |
| Cisco | Ios Xe | 16.3.8 |
| Cisco | Ios Xe | 16.4.1 |
| Cisco | Ios Xe | 16.4.2 |
| Cisco | Ios Xe | 16.4.3 |
| Cisco | Ios Xe | 16.5.1 |
| Cisco | Ios Xe | 16.5.1a |
| Cisco | Ios Xe | 16.5.1b |
| Cisco | Ios Xe | 16.5.2 |
| Cisco | Ios Xe | 16.5.3 |
| Cisco | Ios Xe | 16.6.1 |
| Cisco | Ios Xe | 16.6.2 |
| Cisco | Ios Xe | 16.6.3 |
| Cisco | Ios Xe | 16.7.1 |
| Cisco | Ios Xe | 16.7.1a |
| Cisco | Ios Xe | 16.7.1b |
| Cisco | Ios Xe | 16.8.1 |
| Cisco | Ios Xe | 16.8.1a |
| Cisco | Ios Xe | 16.8.1b |
| Cisco | Ios Xe | 16.8.1c |
| Cisco | Ios Xe | 16.8.1d |
| Cisco | Ios Xe | 16.8.1e |
| Cisco | Ios Xe | 16.8.1s |
References
- http://www.securityfocus.com/bid/107380Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/107380Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-1755?
How severe is CVE-2019-1755?
How do I fix CVE-2019-1755?
Are you affected by CVE-2019-1755?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
