CVE-2019-1746 is a denial-of-service vulnerability affecting Cisco IOS and IOS XE Software, specifically within the Cluster Management Protocol (CMP) processing code. An unauthenticated, adjacent attacker can exploit insufficient input validation by sending malicious CMP management packets. This can cause the affected device to crash and automatically reload, leading to a denial of service. While rated Medium severity (CVSS 6.5) due to its adjacent attack vector, there is no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.1\(6\)ea1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.1\(6\)ea1:*:*:*:*:*:*:* | ||
12.1\(6\)ea1aCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.1\(6\)ea1a:*:*:*:*:*:*:* | ||
12.1\(6\)ea2CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.1\(6\)ea2:*:*:*:*:*:*:* | ||
12.1\(6\)ea2aCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.1\(6\)ea2a:*:*:*:*:*:*:* | ||
12.1\(6\)ea2bCPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.1\(6\)ea2b:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.