CVE-2019-1756 is a critical input validation vulnerability in Cisco IOS XE Software that allows an authenticated, remote attacker with administrator privileges to execute arbitrary commands as the root user on the underlying Linux shell. This flaw, rated 7.2 HIGH on the CVSS scale, stems from improper sanitization of user-supplied input in the web UI, enabling a complete system compromise. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the high privileges granted upon successful exploitation warrant attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.0\(20.3\)CPE matchmatch criteria | cpe:2.3:o:cisco:ios:11.0\(20.3\):*:*:*:*:*:*:* | ||
16.9\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:ios:16.9\(1\):*:*:*:*:*:*:* | ||
3.2.0jaCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.2.0ja:*:*:*:*:*:*:* | ||
16.7.1CPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:16.7.1:*:*:*:*:*:*:* | ||
16.7.1aCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:16.7.1a:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.