CVE-2019-12660 describes a medium-severity vulnerability in the CLI of Cisco IOS XE Software, allowing an authenticated, local attacker to modify device memory due to improper input validation. Exploitation requires authenticated access and specific CLI commands, potentially leading to configuration changes that compromise device security and functionality. While no public exploits or active exploitation have been observed, and community discussion is minimal, the vulnerability carries a CVSS score of 5.5.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 16.1.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.