CVE-2019-1761

MEDIUMCVSS 4.3/10EPSS 0.63%

Last modified

CVE-2019-1761 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. A vulnerability in the Hot Standby Router Protocol (HSRP) subsystem of Cisco IOS and IOS XE Software could allow an unauthenticated, adjacent attacker to receive potentially sensitive information from an affected device. The vulnerability is due to insufficient memory initialization. EPSS estimates a 0.63% chance of exploitation in the next 30 days.

Description

A vulnerability in the Hot Standby Router Protocol (HSRP) subsystem of Cisco IOS and IOS XE Software could allow an unauthenticated, adjacent attacker to receive potentially sensitive information from an affected device. The vulnerability is due to insufficient memory initialization. An attacker could exploit this vulnerability by receiving HSRPv2 traffic from an adjacent HSRP member. A successful exploit could allow the attacker to receive potentially sensitive information from the adjacent device.

Metrics

CVSS 3.1
4.3/10

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS Probability
0.63%

45.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
CiscoIos12.2\(6\)i1
CiscoIos12.2\(33\)cx
CiscoIos12.2\(33\)cy
CiscoIos12.2\(33\)cy1
CiscoIos12.2\(33\)cy2
CiscoIos12.2\(33\)ira
CiscoIos12.2\(33\)irb
CiscoIos12.2\(33\)irc
CiscoIos12.2\(33\)ird
CiscoIos12.2\(33\)ire
CiscoIos12.2\(33\)ire1
CiscoIos12.2\(33\)ire2
CiscoIos12.2\(33\)irf
CiscoIos12.2\(33\)irg
CiscoIos12.2\(33\)irg1
CiscoIos12.2\(33\)irh
CiscoIos12.2\(33\)irh1
CiscoIos12.2\(33\)mra
CiscoIos12.2\(33\)mrb
CiscoIos12.2\(33\)mrb1
CiscoIos12.2\(33\)mrb2
CiscoIos12.2\(33\)mrb3
CiscoIos12.2\(33\)mrb4
CiscoIos12.2\(33\)mrb5
CiscoIos12.2\(33\)mrb6
CiscoIos12.2\(33\)sb
CiscoIos12.2\(33\)sb1
CiscoIos12.2\(33\)sb1a
CiscoIos12.2\(33\)sb1b
CiscoIos12.2\(33\)sb2
CiscoIos12.2\(33\)sb3
CiscoIos12.2\(33\)sb4
CiscoIos12.2\(33\)sb5
CiscoIos12.2\(33\)sb6
CiscoIos12.2\(33\)sb6a
CiscoIos12.2\(33\)sb6b
CiscoIos12.2\(33\)sb7
CiscoIos12.2\(33\)sb8
CiscoIos12.2\(33\)sb8a
CiscoIos12.2\(33\)sb8b
CiscoIos12.2\(33\)sb8c
CiscoIos12.2\(33\)sb8d
CiscoIos12.2\(33\)sb8e
CiscoIos12.2\(33\)sb8f
CiscoIos12.2\(33\)sb8g
CiscoIos12.2\(33\)sb9
CiscoIos12.2\(33\)sb10
CiscoIos12.2\(33\)sb11
CiscoIos12.2\(33\)sb12
CiscoIos12.2\(33\)sb13

Showing 50 of 1761 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2019-1761?
A vulnerability in the Hot Standby Router Protocol (HSRP) subsystem of Cisco IOS and IOS XE Software could allow an unauthenticated, adjacent attacker to receive potentially sensitive information from an affected device. The vulnerability is due to insufficient memory initialization. An attacker could exploit this vulnerability by receiving HSRPv2 traffic from an adjacent HSRP member. A successful exploit could allow the attacker to receive potentially sensitive information from the adjacent device.
How severe is CVE-2019-1761?
CVE-2019-1761 has a CVSS score of 4.3/10 (MEDIUM severity). The EPSS model estimates a 0.63% probability of exploitation in the next 30 days.
How do I fix CVE-2019-1761?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-1761?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST