// For flags

CVE-2019-12647

Cisco IOS and IOS XE Software IP Ident Denial of Service Vulnerability

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

A vulnerability in the Ident protocol handler of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability exists because the affected software incorrectly handles memory structures, leading to a NULL pointer dereference. An attacker could exploit this vulnerability by opening a TCP connection to specific ports and sending traffic over that connection. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition.

Una vulnerabilidad en el manejador del protocolo Ident de los Software Cisco IOS y IOS XE, podría permitir a un atacante remoto no autenticado causar la recarga de un dispositivo afectado. La vulnerabilidad se presenta porque el software afectado maneja incorrectamente las estructuras de la memoria, lo que conlleva a una desreferencia del puntero NULL. Un atacante podría explotar esta vulnerabilidad abriendo una conexión TCP en puertos específicos y mediante el envío de tráfico por medio de ésta conexión. Una explotación con éxito podría permitir al atacante causar que el dispositivo afectado se recargue, resultando en una condición de denegación de servicio (DoS).

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
None
Automatable
Yes
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2019-06-04 CVE Reserved
  • 2019-09-25 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-11-19 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-476: NULL Pointer Dereference
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
1100
Search vendor "Cisco" for product "1100"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
4221
Search vendor "Cisco" for product "4221"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
4321
Search vendor "Cisco" for product "4321"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
4351
Search vendor "Cisco" for product "4351"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
4431
Search vendor "Cisco" for product "4431"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
4451-x
Search vendor "Cisco" for product "4451-x"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 1000
Search vendor "Cisco" for product "Asr 1000"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 1001-hx
Search vendor "Cisco" for product "Asr 1001-hx"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 1001-x
Search vendor "Cisco" for product "Asr 1001-x"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 1002-hx
Search vendor "Cisco" for product "Asr 1002-hx"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 1002-x
Search vendor "Cisco" for product "Asr 1002-x"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 900
Search vendor "Cisco" for product "Asr 900"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 920-10sz-pd
Search vendor "Cisco" for product "Asr 920-10sz-pd"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 920-12cz-a
Search vendor "Cisco" for product "Asr 920-12cz-a"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 920-12cz-d
Search vendor "Cisco" for product "Asr 920-12cz-d"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 920-12sz-im
Search vendor "Cisco" for product "Asr 920-12sz-im"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 920-24sz-im
Search vendor "Cisco" for product "Asr 920-24sz-im"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 920-24sz-m
Search vendor "Cisco" for product "Asr 920-24sz-m"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 920-24tz-m
Search vendor "Cisco" for product "Asr 920-24tz-m"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 920-4sz-a
Search vendor "Cisco" for product "Asr 920-4sz-a"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 920-4sz-d
Search vendor "Cisco" for product "Asr 920-4sz-d"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
Cloud Services Router 1000v
Search vendor "Cisco" for product "Cloud Services Router 1000v"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
Ncs 4201
Search vendor "Cisco" for product "Ncs 4201"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
Ncs 4202
Search vendor "Cisco" for product "Ncs 4202"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
Ncs 4206
Search vendor "Cisco" for product "Ncs 4206"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
Ncs 4216
Search vendor "Cisco" for product "Ncs 4216"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.7.1"
-
Affected
in Cisco
Search vendor "Cisco"
Network Convergence System 520
Search vendor "Cisco" for product "Network Convergence System 520"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
1100
Search vendor "Cisco" for product "1100"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
4221
Search vendor "Cisco" for product "4221"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
4321
Search vendor "Cisco" for product "4321"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
4351
Search vendor "Cisco" for product "4351"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
4431
Search vendor "Cisco" for product "4431"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
4451-x
Search vendor "Cisco" for product "4451-x"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 1000
Search vendor "Cisco" for product "Asr 1000"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 1001-hx
Search vendor "Cisco" for product "Asr 1001-hx"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 1001-x
Search vendor "Cisco" for product "Asr 1001-x"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 1002-hx
Search vendor "Cisco" for product "Asr 1002-hx"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 1002-x
Search vendor "Cisco" for product "Asr 1002-x"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 900
Search vendor "Cisco" for product "Asr 900"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 920-10sz-pd
Search vendor "Cisco" for product "Asr 920-10sz-pd"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 920-12cz-a
Search vendor "Cisco" for product "Asr 920-12cz-a"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 920-12cz-d
Search vendor "Cisco" for product "Asr 920-12cz-d"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 920-12sz-im
Search vendor "Cisco" for product "Asr 920-12sz-im"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 920-24sz-im
Search vendor "Cisco" for product "Asr 920-24sz-im"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 920-24sz-m
Search vendor "Cisco" for product "Asr 920-24sz-m"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 920-24tz-m
Search vendor "Cisco" for product "Asr 920-24tz-m"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 920-4sz-a
Search vendor "Cisco" for product "Asr 920-4sz-a"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
Asr 920-4sz-d
Search vendor "Cisco" for product "Asr 920-4sz-d"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
Cloud Services Router 1000v
Search vendor "Cisco" for product "Cloud Services Router 1000v"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
Ncs 4201
Search vendor "Cisco" for product "Ncs 4201"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
Ncs 4202
Search vendor "Cisco" for product "Ncs 4202"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
Ncs 4206
Search vendor "Cisco" for product "Ncs 4206"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
Ncs 4216
Search vendor "Cisco" for product "Ncs 4216"
--
Safe
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
fuji-16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "fuji-16.8.1"
-
Affected
in Cisco
Search vendor "Cisco"
Network Convergence System 520
Search vendor "Cisco" for product "Network Convergence System 520"
--
Safe