CVE-2019-1950
Last modified
CVE-2019-1950 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, local attacker to gain unauthorized access to an affected device. The vulnerability is due to the existence of default credentials within the default configuration of an affected device. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, local attacker to gain unauthorized access to an affected device. The vulnerability is due to the existence of default credentials within the default configuration of an affected device. An attacker who has access to an affected device could log in with elevated privileges. A successful exploit could allow the attacker to take complete control of the device. This vulnerability affects Cisco devices that are running Cisco IOS XE SD-WAN Software releases 16.11 and earlier.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xe | <= 16.11 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-1950?
How severe is CVE-2019-1950?
How do I fix CVE-2019-1950?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-19493Kentico before 12.0.50 allows file uploads in which the Cont…5.4
- CVE-2019-19494Broadcom based cable modems across multiple vendors are vuln…8.8
- CVE-2019-19495The web interface on the Technicolor TC7230 STEB 01.25 is vu…9.8
- CVE-2019-19496Alfresco Enterprise before 5.2.5 allows stored XSS via an up…5.4
- CVE-2019-19497MDaemon Email Server 17.5.1 allows XSS via the filename of a…5.4
- CVE-2019-19499Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, w…6.5
- CVE-2019-19500Matrix42 Workspace Management 9.1.2.2765 and below allows st…5.4
- CVE-2019-19501VeraCrypt 1.24 allows Local Privilege Escalation during exec…7.8
- CVE-2019-19502Code injection in pluginconfig.php in Image Uploader and Bro…9.8
- CVE-2019-19505Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to…8.8
- CVE-2019-19506Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to…7.5
- CVE-2019-19507In jpv (aka Json Pattern Validator) before 2.1.1, compareCom…5.3
Are you affected by CVE-2019-1950?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
