Vulnerability Database

290,273

Total vulnerabilities in the database

CVE-2019-1755

A vulnerability in the Web Services Management Agent (WSMA) function of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary Cisco IOS commands as a privilege level 15 user. The vulnerability occurs because the affected software improperly sanitizes user-supplied input. An attacker could exploit this vulnerability by submitting crafted HTTP requests to the targeted application. A successful exploit could allow the attacker to execute arbitrary commands on the affected device.

  • Published: Mar 28, 2019
  • Updated: Apr 13, 2023
  • CVE: CVE-2019-1755
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.2
  • AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: High
  • Score: 9
  • AV:N/AC:L/Au:S/C:C/I:C/A:C

CWEs:

Software From Fixed in
cisco / ios_xe 16.2.1 16.2.1.x
cisco / ios_xe 16.1.3 16.1.3.x
cisco / ios_xe 16.1.2 16.1.2.x
cisco / ios_xe 16.6.1 16.6.1.x
cisco / ios_xe 3.2.0ja 3.2.0ja.x
cisco / ios_xe 16.1.1 16.1.1.x
cisco / ios_xe 16.4.1 16.4.1.x
cisco / ios_xe 16.2.2 16.2.2.x
cisco / ios_xe 16.3.1 16.3.1.x
cisco / ios_xe 16.3.1a 16.3.1a.x
cisco / ios_xe 16.3.2 16.3.2.x
cisco / ios_xe 16.3.3 16.3.3.x
cisco / ios_xe 16.5.1 16.5.1.x
cisco / ios_xe 16.5.1a 16.5.1a.x
cisco / ios_xe 16.3.4 16.3.4.x
cisco / ios_xe 16.5.1b 16.5.1b.x
cisco / ios_xe 16.4.2 16.4.2.x
cisco / ios_xe 16.3.5b 16.3.5b.x
cisco / ios_xe 16.3.6 16.3.6.x
cisco / ios_xe 16.6.3 16.6.3.x
cisco / ios_xe 16.8.1 16.8.1.x
cisco / ios_xe 16.7.1 16.7.1.x
cisco / ios_xe 16.6.2 16.6.2.x
cisco / ios_xe 16.3.5 16.3.5.x
cisco / ios_xe 16.5.2 16.5.2.x
cisco / ios_xe 16.8.1a 16.8.1a.x
cisco / ios_xe 16.8.1s 16.8.1s.x
cisco / ios_xe 16.8.1b 16.8.1b.x
cisco / ios_xe 16.8.1d 16.8.1d.x
cisco / ios_xe 16.7.1a 16.7.1a.x
cisco / ios_xe 16.7.1b 16.7.1b.x
cisco / ios_xe 16.8.1c 16.8.1c.x
cisco / ios_xe 16.8.1e 16.8.1e.x
cisco / ios_xe 16.4.3 16.4.3.x
cisco / ios_xe 16.5.3 16.5.3.x
cisco / ios_xe 3.6.10e 3.6.10e.x
cisco / ios_xe 16.3.7 16.3.7.x
cisco / ios_xe 16.3.8 16.3.8.x