CVE-2019-1749 is a denial-of-service vulnerability in Cisco IOS XE Software for ASR 900 Route Switch Processor 3 (RSP3). It allows an unauthenticated, adjacent attacker to trigger a device reload by sending a malformed OSPFv2 message due to insufficient ingress traffic validation. Rated High (CVSS 7.4), this vulnerability has an adjacent attack vector with low complexity, leading to a complete loss of availability. There is no evidence of active exploitation, public exploit code, or significant community discussion regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.13.6asCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.13.6as:*:*:*:*:*:*:* | ||
3.16.0asCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.16.0as:*:*:*:*:*:*:* | ||
3.16.1asCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.16.1as:*:*:*:*:*:*:* | ||
3.16.2asCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.16.2as:*:*:*:*:*:*:* | ||
3.16.3asCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.16.3as:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.