CVE-2019-12671
Cisco IOS XE Software Consent Token Bypass Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execute commands on the underlying operating system (OS). The vulnerability is due to insufficient enforcement of the consent token in authorizing shell access. An attacker could exploit this vulnerability by authenticating to the CLI and requesting shell access on an affected device. A successful exploit could allow the attacker to gain shell access on the affected device and execute commands on the underlying OS.
Una vulnerabilidad en la CLI del Software Cisco IOS XE, podría permitir a un atacante local autenticado conseguir acceso de shell en un dispositivo afectado y ejecutar comandos sobre el sistema operativo (SO) subyacente. La vulnerabilidad es debido a la aplicación insuficiente del token de consentimiento en la autorización del acceso de shell. Un atacante podría explotar esta vulnerabilidad mediante la autenticación en la CLI y solicitando acceso de shell en un dispositivo afectado. Una explotación con éxito podría permitir al atacante conseguir acceso de shell en el dispositivo afectado y ejecutar comandos en el Sistema Operativo subyacente.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2019-06-04 CVE Reserved
- 2019-09-25 CVE Published
- 2023-03-08 EPSS Updated
- 2024-11-20 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-285: Improper Authorization
- CWE-863: Incorrect Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | 4321\/k9-rf Integrated Services Router Search vendor "Cisco" for product "4321\/k9-rf Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | 4321\/k9-ws Integrated Services Router Search vendor "Cisco" for product "4321\/k9-ws Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | 4321\/k9 Integrated Services Router Search vendor "Cisco" for product "4321\/k9 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | 4331\/k9-rf Integrated Services Router Search vendor "Cisco" for product "4331\/k9-rf Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | 4331\/k9-ws Integrated Services Router Search vendor "Cisco" for product "4331\/k9-ws Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | 4331\/k9 Integrated Services Router Search vendor "Cisco" for product "4331\/k9 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | 4351\/k9-rf Integrated Services Router Search vendor "Cisco" for product "4351\/k9-rf Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | 4351\/k9-ws Integrated Services Router Search vendor "Cisco" for product "4351\/k9-ws Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | 4351\/k9 Integrated Services Router Search vendor "Cisco" for product "4351\/k9 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asr1001-hx Search vendor "Cisco" for product "Asr1001-hx" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asr1001-hx-rf Search vendor "Cisco" for product "Asr1001-hx-rf" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asr1001-x Search vendor "Cisco" for product "Asr1001-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asr1001-x-rf Search vendor "Cisco" for product "Asr1001-x-rf" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asr1001-x-ws Search vendor "Cisco" for product "Asr1001-x-ws" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asr1002-hx Search vendor "Cisco" for product "Asr1002-hx" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asr1002-hx-rf Search vendor "Cisco" for product "Asr1002-hx-rf" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asr1002-hx-ws Search vendor "Cisco" for product "Asr1002-hx-ws" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asr1002-x Search vendor "Cisco" for product "Asr1002-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asr1002-x-rf Search vendor "Cisco" for product "Asr1002-x-rf" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Asr1002-x-ws Search vendor "Cisco" for product "Asr1002-x-ws" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | C1117-4p Search vendor "Cisco" for product "C1117-4p" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | C1117-4plteea Search vendor "Cisco" for product "C1117-4plteea" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | C1117-4pltela Search vendor "Cisco" for product "C1117-4pltela" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Encs5412\/k9 Search vendor "Cisco" for product "Encs5412\/k9" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Encs5412\/k9-rf Search vendor "Cisco" for product "Encs5412\/k9-rf" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sasr1k1xucmk9-1610 Search vendor "Cisco" for product "Sasr1k1xucmk9-1610" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sasr1k2xucmk9-1610 Search vendor "Cisco" for product "Sasr1k2xucmk9-1610" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sasr1khxucmk9-1610 Search vendor "Cisco" for product "Sasr1khxucmk9-1610" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | - |
Affected
| in | Cisco Search vendor "Cisco" | Sisr1100ucmk9-1610 Search vendor "Cisco" for product "Sisr1100ucmk9-1610" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | 4321\/k9-rf Integrated Services Router Search vendor "Cisco" for product "4321\/k9-rf Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | 4321\/k9-ws Integrated Services Router Search vendor "Cisco" for product "4321\/k9-ws Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | 4321\/k9 Integrated Services Router Search vendor "Cisco" for product "4321\/k9 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | 4331\/k9-rf Integrated Services Router Search vendor "Cisco" for product "4331\/k9-rf Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | 4331\/k9-ws Integrated Services Router Search vendor "Cisco" for product "4331\/k9-ws Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | 4331\/k9 Integrated Services Router Search vendor "Cisco" for product "4331\/k9 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | 4351\/k9-rf Integrated Services Router Search vendor "Cisco" for product "4351\/k9-rf Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | 4351\/k9-ws Integrated Services Router Search vendor "Cisco" for product "4351\/k9-ws Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | 4351\/k9 Integrated Services Router Search vendor "Cisco" for product "4351\/k9 Integrated Services Router" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | Asr1001-hx Search vendor "Cisco" for product "Asr1001-hx" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | Asr1001-hx-rf Search vendor "Cisco" for product "Asr1001-hx-rf" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | Asr1001-x Search vendor "Cisco" for product "Asr1001-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | Asr1001-x-rf Search vendor "Cisco" for product "Asr1001-x-rf" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | Asr1001-x-ws Search vendor "Cisco" for product "Asr1001-x-ws" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | Asr1002-hx Search vendor "Cisco" for product "Asr1002-hx" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | Asr1002-hx-rf Search vendor "Cisco" for product "Asr1002-hx-rf" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | Asr1002-hx-ws Search vendor "Cisco" for product "Asr1002-hx-ws" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | Asr1002-x Search vendor "Cisco" for product "Asr1002-x" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | Asr1002-x-rf Search vendor "Cisco" for product "Asr1002-x-rf" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | Asr1002-x-ws Search vendor "Cisco" for product "Asr1002-x-ws" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | C1117-4p Search vendor "Cisco" for product "C1117-4p" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | C1117-4plteea Search vendor "Cisco" for product "C1117-4plteea" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | C1117-4pltela Search vendor "Cisco" for product "C1117-4pltela" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | Encs5412\/k9 Search vendor "Cisco" for product "Encs5412\/k9" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | Encs5412\/k9-rf Search vendor "Cisco" for product "Encs5412\/k9-rf" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | Sasr1k1xucmk9-1610 Search vendor "Cisco" for product "Sasr1k1xucmk9-1610" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | Sasr1k2xucmk9-1610 Search vendor "Cisco" for product "Sasr1k2xucmk9-1610" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | Sasr1khxucmk9-1610 Search vendor "Cisco" for product "Sasr1khxucmk9-1610" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Ios Xe Search vendor "Cisco" for product "Ios Xe" | 16.11.1 Search vendor "Cisco" for product "Ios Xe" and version "16.11.1" | a |
Affected
| in | Cisco Search vendor "Cisco" | Sisr1100ucmk9-1610 Search vendor "Cisco" for product "Sisr1100ucmk9-1610" | - | - |
Safe
|