CVE-2019-1753 is a high-severity vulnerability in the web UI of Cisco IOS XE Software, allowing an authenticated but unprivileged remote attacker to execute arbitrary Cisco IOS commands with higher privileges. This is due to insufficient input validation in Web Services Management Agent (WSMA) functions. The CVSS score is 8.8, indicating a network-exploitable vulnerability with low attack complexity and high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the potential for privilege escalation makes it a significant risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.2.0jaCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.2.0ja:*:*:*:*:*:*:* | ||
3.6.10eCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.6.10e:*:*:*:*:*:*:* | ||
16.6.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:16.6.1:*:*:*:*:*:*:* | ||
16.6.2CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:16.6.2:*:*:*:*:*:*:* | ||
16.6.3CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:16.6.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.