// For flags

CVE-2019-1759

Cisco IOS XE Software Gigabit Ethernet Management Interface Access Control List Bypass Vulnerability

Severity Score

5.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to reach the configured IP addresses on the Gigabit Ethernet Management interface. The vulnerability is due to a logic error that was introduced in the Cisco IOS XE Software 16.1.1 Release, which prevents the ACL from working when applied against the management interface. An attacker could exploit this issue by attempting to access the device via the management interface.

Una vulnerabilidad en la funcionalidad de listas de control de acceso (ACL) de la interfaz Gigabit Ethernet Management del software Cisco IOS XE podría permitir que un atacante remoto no autenticado alcance las direcciones IP configuradas de la interfaz Gigabit Ethernet Management. La vulnerabilidad se debe a un error de lógica que se introdujo en la versión 16.1.1 del software Cisco IOS XE, que evita que la ACL trabaje cuando se aplica contra la interfaz de gestión. Un atacante podría explotar este problema intentando acceder al dispositivo mediante la interfaz de gestión.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
None
Automatable
Yes
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2018-12-06 CVE Reserved
  • 2019-03-28 CVE Published
  • 2020-05-15 First Exploit
  • 2024-08-17 EPSS Updated
  • 2024-11-19 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-284: Improper Access Control
  • CWE-287: Improper Authentication
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
3.2.0ja
Search vendor "Cisco" for product "Ios Xe" and version "3.2.0ja"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.2.1
Search vendor "Cisco" for product "Ios Xe" and version "16.2.1"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.2.2
Search vendor "Cisco" for product "Ios Xe" and version "16.2.2"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.3.1
Search vendor "Cisco" for product "Ios Xe" and version "16.3.1"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.3.1a
Search vendor "Cisco" for product "Ios Xe" and version "16.3.1a"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.3.2
Search vendor "Cisco" for product "Ios Xe" and version "16.3.2"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.3.3
Search vendor "Cisco" for product "Ios Xe" and version "16.3.3"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.3.4
Search vendor "Cisco" for product "Ios Xe" and version "16.3.4"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.3.5
Search vendor "Cisco" for product "Ios Xe" and version "16.3.5"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.3.5b
Search vendor "Cisco" for product "Ios Xe" and version "16.3.5b"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.3.6
Search vendor "Cisco" for product "Ios Xe" and version "16.3.6"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.3.7
Search vendor "Cisco" for product "Ios Xe" and version "16.3.7"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.4.1
Search vendor "Cisco" for product "Ios Xe" and version "16.4.1"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.4.2
Search vendor "Cisco" for product "Ios Xe" and version "16.4.2"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.4.3
Search vendor "Cisco" for product "Ios Xe" and version "16.4.3"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.5.1
Search vendor "Cisco" for product "Ios Xe" and version "16.5.1"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.5.1a
Search vendor "Cisco" for product "Ios Xe" and version "16.5.1a"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.5.1b
Search vendor "Cisco" for product "Ios Xe" and version "16.5.1b"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.5.2
Search vendor "Cisco" for product "Ios Xe" and version "16.5.2"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.5.3
Search vendor "Cisco" for product "Ios Xe" and version "16.5.3"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.6.1
Search vendor "Cisco" for product "Ios Xe" and version "16.6.1"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.6.2
Search vendor "Cisco" for product "Ios Xe" and version "16.6.2"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.6.3
Search vendor "Cisco" for product "Ios Xe" and version "16.6.3"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.6.4
Search vendor "Cisco" for product "Ios Xe" and version "16.6.4"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.6.4a
Search vendor "Cisco" for product "Ios Xe" and version "16.6.4a"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.6.4s
Search vendor "Cisco" for product "Ios Xe" and version "16.6.4s"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.7.1
Search vendor "Cisco" for product "Ios Xe" and version "16.7.1"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.7.1a
Search vendor "Cisco" for product "Ios Xe" and version "16.7.1a"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.7.1b
Search vendor "Cisco" for product "Ios Xe" and version "16.7.1b"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.7.2
Search vendor "Cisco" for product "Ios Xe" and version "16.7.2"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.8.1
Search vendor "Cisco" for product "Ios Xe" and version "16.8.1"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.8.1a
Search vendor "Cisco" for product "Ios Xe" and version "16.8.1a"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.8.1b
Search vendor "Cisco" for product "Ios Xe" and version "16.8.1b"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.8.1c
Search vendor "Cisco" for product "Ios Xe" and version "16.8.1c"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.8.1d
Search vendor "Cisco" for product "Ios Xe" and version "16.8.1d"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.8.1e
Search vendor "Cisco" for product "Ios Xe" and version "16.8.1e"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.8.1s
Search vendor "Cisco" for product "Ios Xe" and version "16.8.1s"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.8.2
Search vendor "Cisco" for product "Ios Xe" and version "16.8.2"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.9.1
Search vendor "Cisco" for product "Ios Xe" and version "16.9.1"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.9.1a
Search vendor "Cisco" for product "Ios Xe" and version "16.9.1a"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.9.1b
Search vendor "Cisco" for product "Ios Xe" and version "16.9.1b"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.9.1c
Search vendor "Cisco" for product "Ios Xe" and version "16.9.1c"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.9.1d
Search vendor "Cisco" for product "Ios Xe" and version "16.9.1d"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.9.1s
Search vendor "Cisco" for product "Ios Xe" and version "16.9.1s"
-
Affected
Cisco
Search vendor "Cisco"
Ios Xe
Search vendor "Cisco" for product "Ios Xe"
16.9.2
Search vendor "Cisco" for product "Ios Xe" and version "16.9.2"
-
Affected