CVE-2019-12624 is a Cross-Site Request Forgery (CSRF) vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controllers (NGWC). An unauthenticated, remote attacker could exploit this by tricking an authenticated user into clicking a crafted link, allowing the attacker to perform arbitrary actions with the user's privileges. This vulnerability has a high CVSS score of 8.8, indicating significant potential impact including full compromise of confidentiality, integrity, and availability. While not actively exploited in the wild (KEV: No), public exploit code exists on ExploitDB, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.xe, <= 3.11.xeCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.