CVE-2019-1950
Last modified
CVE-2019-1950 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, local attacker to gain unauthorized access to an affected device. The vulnerability is due to the existence of default credentials within the default configuration of an affected device. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, local attacker to gain unauthorized access to an affected device. The vulnerability is due to the existence of default credentials within the default configuration of an affected device. An attacker who has access to an affected device could log in with elevated privileges. A successful exploit could allow the attacker to take complete control of the device. This vulnerability affects Cisco devices that are running Cisco IOS XE SD-WAN Software releases 16.11 and earlier.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xe | <= 16.11 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-1950?
How severe is CVE-2019-1950?
How do I fix CVE-2019-1950?
Are you affected by CVE-2019-1950?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
