CVE-2019-1745 is a command injection vulnerability in Cisco IOS XE Software, allowing an authenticated local attacker to execute arbitrary commands with elevated privileges. This flaw stems from insufficient input validation, enabling an attacker to gain root access by submitting crafted input. Rated 7.8 HIGH on CVSS, it requires local authentication and has high impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code, or significant community discussion for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.6.10eCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.6.10e:*:*:*:*:*:*:* | ||
3.10.0sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.10.0s:*:*:*:*:*:*:* | ||
3.10.1sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.10.1s:*:*:*:*:*:*:* | ||
3.10.2asCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.10.2as:*:*:*:*:*:*:* | ||
3.10.2sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.10.2s:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.