// For flags

CVE-2019-12643

Cisco REST API Container for IOS XE Software Authentication Bypass Vulnerability

Severity Score

10.0
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass authentication on the managed Cisco IOS XE device. The vulnerability is due to an improper check performed by the area of code that manages the REST API authentication service. An attacker could exploit this vulnerability by submitting malicious HTTP requests to the targeted device. A successful exploit could allow the attacker to obtain the token-id of an authenticated user. This token-id could be used to bypass authentication and execute privileged actions through the interface of the REST API virtual service container on the affected Cisco IOS XE device. The REST API interface is not enabled by default and must be installed and activated separately on IOS XE devices. See the Details section for more information.

Una vulnerabilidad en el contenedor de servicios virtuales API REST de Cisco para el software Cisco IOS XE podría permitir que un atacante remoto no identificado omita la autenticación en el dispositivo Cisco IOS XE administrado. La vulnerabilidad se debe a una verificación incorrecta realizada por el área de código que administra el servicio de autenticación API REST. Un atacante podría aprovechar esta vulnerabilidad al enviar solicitudes HTTP maliciosas al dispositivo objetivo. Una explotación con éxito podría permitir al atacante obtener el identificador de token de un usuario identificado. Este token-id podría usarse para omitir la autenticación y ejecutar acciones privilegiadas a través de la interfaz del contenedor del servicio virtual REST API en el dispositivo Cisco IOS XE afectado. La interfaz REST API no está habilitada de manera predeterminada y debe instalarse y activarse por separado en dispositivos IOS XE. Vea la sección Detalles para más informació

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
None
Automatable
Yes
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2019-06-04 CVE Reserved
  • 2019-08-28 CVE Published
  • 2024-07-19 EPSS Updated
  • 2024-11-19 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-287: Improper Authentication
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
15.5\(3\)s3.16
Search vendor "Cisco" for product "Ios Xe" and version "15.5\(3\)s3.16"
-
Affected
in Cisco
Search vendor "Cisco"
4221 Integrated Services Router
Search vendor "Cisco" for product "4221 Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
15.5\(3\)s3.16
Search vendor "Cisco" for product "Ios Xe" and version "15.5\(3\)s3.16"
-
Affected
in Cisco
Search vendor "Cisco"
4321 Integrated Services Router
Search vendor "Cisco" for product "4321 Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
15.5\(3\)s3.16
Search vendor "Cisco" for product "Ios Xe" and version "15.5\(3\)s3.16"
-
Affected
in Cisco
Search vendor "Cisco"
4331 Integrated Services Router
Search vendor "Cisco" for product "4331 Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
15.5\(3\)s3.16
Search vendor "Cisco" for product "Ios Xe" and version "15.5\(3\)s3.16"
-
Affected
in Cisco
Search vendor "Cisco"
4351 Integrated Services Router
Search vendor "Cisco" for product "4351 Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
15.5\(3\)s3.16
Search vendor "Cisco" for product "Ios Xe" and version "15.5\(3\)s3.16"
-
Affected
in Cisco
Search vendor "Cisco"
4431 Integrated Services Router
Search vendor "Cisco" for product "4431 Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
15.5\(3\)s3.16
Search vendor "Cisco" for product "Ios Xe" and version "15.5\(3\)s3.16"
-
Affected
in Cisco
Search vendor "Cisco"
4451-x Integrated Services Router
Search vendor "Cisco" for product "4451-x Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
15.5\(3\)s3.16
Search vendor "Cisco" for product "Ios Xe" and version "15.5\(3\)s3.16"
-
Affected
in Cisco
Search vendor "Cisco"
Cloud Services Router 1000v
Search vendor "Cisco" for product "Cloud Services Router 1000v"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.6.5
Search vendor "Cisco" for product "Ios Xe" and version "16.6.5"
-
Affected
in Cisco
Search vendor "Cisco"
4221 Integrated Services Router
Search vendor "Cisco" for product "4221 Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.6.5
Search vendor "Cisco" for product "Ios Xe" and version "16.6.5"
-
Affected
in Cisco
Search vendor "Cisco"
4321 Integrated Services Router
Search vendor "Cisco" for product "4321 Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.6.5
Search vendor "Cisco" for product "Ios Xe" and version "16.6.5"
-
Affected
in Cisco
Search vendor "Cisco"
4331 Integrated Services Router
Search vendor "Cisco" for product "4331 Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.6.5
Search vendor "Cisco" for product "Ios Xe" and version "16.6.5"
-
Affected
in Cisco
Search vendor "Cisco"
4351 Integrated Services Router
Search vendor "Cisco" for product "4351 Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.6.5
Search vendor "Cisco" for product "Ios Xe" and version "16.6.5"
-
Affected
in Cisco
Search vendor "Cisco"
4431 Integrated Services Router
Search vendor "Cisco" for product "4431 Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.6.5
Search vendor "Cisco" for product "Ios Xe" and version "16.6.5"
-
Affected
in Cisco
Search vendor "Cisco"
4451-x Integrated Services Router
Search vendor "Cisco" for product "4451-x Integrated Services Router"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.6.5
Search vendor "Cisco" for product "Ios Xe" and version "16.6.5"
-
Affected
in Cisco
Search vendor "Cisco"
Cloud Services Router 1000v
Search vendor "Cisco" for product "Cloud Services Router 1000v"
--
Safe