CVE-2019-1755
Last modified
CVE-2019-1755 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A vulnerability in the Web Services Management Agent (WSMA) function of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary Cisco IOS commands as a privilege level 15 user. The vulnerability occurs because the affected software improperly sanitizes user-supplied input. EPSS estimates a 3.45% chance of exploitation in the next 30 days.
Description
A vulnerability in the Web Services Management Agent (WSMA) function of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary Cisco IOS commands as a privilege level 15 user. The vulnerability occurs because the affected software improperly sanitizes user-supplied input. An attacker could exploit this vulnerability by submitting crafted HTTP requests to the targeted application. A successful exploit could allow the attacker to execute arbitrary commands on the affected device.
Metrics
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xe | 3.2.0ja |
| Cisco | Ios Xe | 3.6.10e |
| Cisco | Ios Xe | 16.1.1 |
| Cisco | Ios Xe | 16.1.2 |
| Cisco | Ios Xe | 16.1.3 |
| Cisco | Ios Xe | 16.2.1 |
| Cisco | Ios Xe | 16.2.2 |
| Cisco | Ios Xe | 16.3.1 |
| Cisco | Ios Xe | 16.3.1a |
| Cisco | Ios Xe | 16.3.2 |
| Cisco | Ios Xe | 16.3.3 |
| Cisco | Ios Xe | 16.3.4 |
| Cisco | Ios Xe | 16.3.5 |
| Cisco | Ios Xe | 16.3.5b |
| Cisco | Ios Xe | 16.3.6 |
| Cisco | Ios Xe | 16.3.7 |
| Cisco | Ios Xe | 16.3.8 |
| Cisco | Ios Xe | 16.4.1 |
| Cisco | Ios Xe | 16.4.2 |
| Cisco | Ios Xe | 16.4.3 |
| Cisco | Ios Xe | 16.5.1 |
| Cisco | Ios Xe | 16.5.1a |
| Cisco | Ios Xe | 16.5.1b |
| Cisco | Ios Xe | 16.5.2 |
| Cisco | Ios Xe | 16.5.3 |
| Cisco | Ios Xe | 16.6.1 |
| Cisco | Ios Xe | 16.6.2 |
| Cisco | Ios Xe | 16.6.3 |
| Cisco | Ios Xe | 16.7.1 |
| Cisco | Ios Xe | 16.7.1a |
| Cisco | Ios Xe | 16.7.1b |
| Cisco | Ios Xe | 16.8.1 |
| Cisco | Ios Xe | 16.8.1a |
| Cisco | Ios Xe | 16.8.1b |
| Cisco | Ios Xe | 16.8.1c |
| Cisco | Ios Xe | 16.8.1d |
| Cisco | Ios Xe | 16.8.1e |
| Cisco | Ios Xe | 16.8.1s |
References
- http://www.securityfocus.com/bid/107380Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/107380Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-1755?
How severe is CVE-2019-1755?
How do I fix CVE-2019-1755?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-17543LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_wri…8.1
- CVE-2019-17544libaspell.a in GNU Aspell before 0.60.8 has a stack-based bu…9.1
- CVE-2019-17545GDAL through 3.0.1 has a poolDestroy double free in OGRExpat…9.8
- CVE-2019-17546tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL th…8.8
- CVE-2019-17547In ImageMagick before 7.0.8-62, TraceBezier in MagickCore/dr…8.8
- CVE-2019-17549ESET Cyber Security before 6.8.1.0 is vulnerable to a denial…6.5
- CVE-2019-17550The Blog2Social plugin before 5.9.0 for WordPress is affecte…6.1
- CVE-2019-17551In Apak Wholesale Floorplanning Finance 6.31.8.3 and 6.31.8.…6.1
- CVE-2019-17552An issue was discovered in idreamsoft iCMS v7.0.14. There is…9.8
- CVE-2019-17553An issue was discovered in MetInfo v7.0.0 beta. There is SQL…9.8
- CVE-2019-17554The XML content type entity deserializer in Apache Olingo ve…5.5
- CVE-2019-17555The AsyncResponseWrapperImpl class in Apache Olingo versions…7.5
Are you affected by CVE-2019-1755?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
