5.9

CVE-2019-1757

A vulnerability in the Cisco Smart Call Home feature of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data using an invalid certificate. The vulnerability is due to insufficient certificate validation by the affected software. An attacker could exploit this vulnerability by supplying a crafted certificate to an affected device. A successful exploit could allow the attacker to conduct man-in-the-middle attacks to decrypt confidential information on user connections to the affected software.

Data is provided by the National Vulnerability Database (NVD)
CiscoIos Version2.3
CiscoIos Version12.2(6)i1
CiscoIos Version12.4(25e)jap1m
CiscoIos Version12.4(25e)jap2
CiscoIos Version12.4(25e)jap26
CiscoIos Version12.4(25e)jaz1
CiscoIos Version15.1(2)sg8a
CiscoIos Version15.1(3)svg3d
CiscoIos Version15.1(3)svi1b
CiscoIos Version15.1(3)svm3
CiscoIos Version15.1(3)svn2
CiscoIos Version15.1(3)svo1
CiscoIos Version15.1(3)svo2
CiscoIos Version15.1(3)svp1
CiscoIos Version15.1(4)m12c
CiscoIos Version15.2(2)e4
CiscoIos Version15.2(2)e5
CiscoIos Version15.2(2)e5a
CiscoIos Version15.2(2)e5b
CiscoIos Version15.2(2)e6
CiscoIos Version15.2(2)e7
CiscoIos Version15.2(2)e7b
CiscoIos Version15.2(2)e8
CiscoIos Version15.2(3)e4
CiscoIos Version15.2(3)e5
CiscoIos Version15.2(3)ea1
CiscoIos Version15.2(4)e2
CiscoIos Version15.2(4)e3
CiscoIos Version15.2(4)e4
CiscoIos Version15.2(4)e5
CiscoIos Version15.2(4)e5a
CiscoIos Version15.2(4)e6
CiscoIos Version15.2(4)ea8
CiscoIos Version15.2(4)ea9
CiscoIos Version15.2(4)jaz1
CiscoIos Version15.2(4)jn1
CiscoIos Version15.2(4a)ea5
CiscoIos Version15.2(4m)e2
CiscoIos Version15.2(4m)e3
CiscoIos Version15.2(4n)e2
CiscoIos Version15.2(4o)e2
CiscoIos Version15.2(4o)e3
CiscoIos Version15.2(4p)e1
CiscoIos Version15.2(4q)e1
CiscoIos Version15.2(4s)e1
CiscoIos Version15.2(4s)e2
CiscoIos Version15.2(5)e
CiscoIos Version15.2(5)e1
CiscoIos Version15.2(5)e2
CiscoIos Version15.2(5)e2b
CiscoIos Version15.2(5)e2c
CiscoIos Version15.2(5)ea
CiscoIos Version15.2(5)ex
CiscoIos Version15.2(5a)e
CiscoIos Version15.2(5a)e1
CiscoIos Version15.2(5b)e
CiscoIos Version15.2(5c)e
CiscoIos Version15.2(6)e
CiscoIos Version15.2(6)e0a
CiscoIos Version15.2(6)e0c
CiscoIos Version15.2(6)e1
CiscoIos Version15.2(6)e1a
CiscoIos Version15.2(6)e1s
CiscoIos Version15.3(3)ja1n
CiscoIos Version15.3(3)jd15
CiscoIos Version15.3(3)jda15
CiscoIos Version15.3(3)jf35
CiscoIos Version15.3(3)ji
CiscoIos Version15.3(3)ji2
CiscoIos Version15.3(3)jn1
CiscoIos Version15.3(3)jn2
CiscoIos Version15.5(3)s1
CiscoIos Version15.5(3)s1a
CiscoIos Version15.5(3)s2
CiscoIos Version15.5(3)s3
CiscoIos Version15.5(3)s4
CiscoIos Version15.5(3)s5
CiscoIos Version15.5(3)s6
CiscoIos Version15.5(3)s6a
CiscoIos Version15.5(3)s6b
CiscoIos Version15.5(3)s7
CiscoIos Version15.6(1)s
CiscoIos Version15.6(1)s1
CiscoIos Version15.6(1)s2
CiscoIos Version15.6(1)s3
CiscoIos Version15.6(1)s4
CiscoIos Version15.6(1)sn
CiscoIos Version15.6(1)sn1
CiscoIos Version15.6(1)sn2
CiscoIos Version15.6(1)sn3
CiscoIos Version15.6(1)t
CiscoIos Version15.6(1)t0a
CiscoIos Version15.6(1)t1
CiscoIos Version15.6(1)t2
CiscoIos Version15.6(1)t3
CiscoIos Version15.6(2)s
CiscoIos Version15.6(2)s1
CiscoIos Version15.6(2)s2
CiscoIos Version15.6(2)s3
CiscoIos Version15.6(2)s4
CiscoIos Version15.6(2)sn
CiscoIos Version15.6(2)sp
CiscoIos Version15.6(2)sp1
CiscoIos Version15.6(2)sp2
CiscoIos Version15.6(2)sp3
CiscoIos Version15.6(2)sp3b
CiscoIos Version15.6(2)sp4
CiscoIos Version15.6(2)t
CiscoIos Version15.6(2)t0a
CiscoIos Version15.6(2)t1
CiscoIos Version15.6(2)t2
CiscoIos Version15.6(2)t3
CiscoIos Version15.6(3)m
CiscoIos Version15.6(3)m0a
CiscoIos Version15.6(3)m1
CiscoIos Version15.6(3)m1a
CiscoIos Version15.6(3)m1b
CiscoIos Version15.6(3)m2
CiscoIos Version15.6(3)m2a
CiscoIos Version15.6(3)m3
CiscoIos Version15.6(3)m3a
CiscoIos Version15.6(3)m4
CiscoIos Version15.6(3)sn
CiscoIos Version15.6(4)sn
CiscoIos Version15.6(5)sn
CiscoIos Version15.6(6)sn
CiscoIos Version15.6(7)sn
CiscoIos Version15.7(3)m
CiscoIos Version15.7(3)m0a
CiscoIos Version15.7(3)m1
CiscoIos Version15.7(3)m2
CiscoIos Xe Version3.6.4e
CiscoIos Xe Version3.6.5ae
CiscoIos Xe Version3.6.5be
CiscoIos Xe Version3.6.5e
CiscoIos Xe Version3.6.6e
CiscoIos Xe Version3.6.7ae
CiscoIos Xe Version3.6.7be
CiscoIos Xe Version3.6.7e
CiscoIos Xe Version3.6.8e
CiscoIos Xe Version3.7.4e
CiscoIos Xe Version3.7.5e
CiscoIos Xe Version3.8.2e
CiscoIos Xe Version3.8.3e
CiscoIos Xe Version3.8.4e
CiscoIos Xe Version3.8.5ae
CiscoIos Xe Version3.8.5e
CiscoIos Xe Version3.8.6e
CiscoIos Xe Version3.9.0e
CiscoIos Xe Version3.9.1e
CiscoIos Xe Version3.9.2be
CiscoIos Xe Version3.9.2e
CiscoIos Xe Version3.10.0ce
CiscoIos Xe Version3.10.0e
CiscoIos Xe Version3.10.1ae
CiscoIos Xe Version3.10.1e
CiscoIos Xe Version3.10.1se
CiscoIos Xe Version3.16.1as
CiscoIos Xe Version3.16.1s
CiscoIos Xe Version3.16.2as
CiscoIos Xe Version3.16.2bs
CiscoIos Xe Version3.16.2s
CiscoIos Xe Version3.16.3as
CiscoIos Xe Version3.16.3s
CiscoIos Xe Version3.16.4as
CiscoIos Xe Version3.16.4bs
CiscoIos Xe Version3.16.4cs
CiscoIos Xe Version3.16.4ds
CiscoIos Xe Version3.16.4es
CiscoIos Xe Version3.16.4gs
CiscoIos Xe Version3.16.4s
CiscoIos Xe Version3.16.5as
CiscoIos Xe Version3.16.5bs
CiscoIos Xe Version3.16.5s
CiscoIos Xe Version3.16.6bs
CiscoIos Xe Version3.16.6s
CiscoIos Xe Version3.16.7as
CiscoIos Xe Version3.16.7bs
CiscoIos Xe Version3.16.7s
CiscoIos Xe Version3.17.0s
CiscoIos Xe Version3.17.1as
CiscoIos Xe Version3.17.1s
CiscoIos Xe Version3.17.3s
CiscoIos Xe Version3.17.4s
CiscoIos Xe Version3.18.0as
CiscoIos Xe Version3.18.0s
CiscoIos Xe Version3.18.0sp
CiscoIos Xe Version3.18.1asp
CiscoIos Xe Version3.18.1bsp
CiscoIos Xe Version3.18.1csp
CiscoIos Xe Version3.18.1gsp
CiscoIos Xe Version3.18.1hsp
CiscoIos Xe Version3.18.1isp
CiscoIos Xe Version3.18.1s
CiscoIos Xe Version3.18.1sp
CiscoIos Xe Version3.18.2asp
CiscoIos Xe Version3.18.2s
CiscoIos Xe Version3.18.2sp
CiscoIos Xe Version3.18.3asp
CiscoIos Xe Version3.18.3bsp
CiscoIos Xe Version3.18.3s
CiscoIos Xe Version3.18.3sp
CiscoIos Xe Version3.18.4s
CiscoIos Xe Version3.18.4sp
CiscoIos Xe Version16.2.1
CiscoIos Xe Version16.2.2
CiscoIos Xe Version16.3.1
CiscoIos Xe Version16.3.1a
CiscoIos Xe Version16.3.2
CiscoIos Xe Version16.3.3
CiscoIos Xe Version16.3.4
CiscoIos Xe Version16.3.5
CiscoIos Xe Version16.3.5b
CiscoIos Xe Version16.3.6
CiscoIos Xe Version16.4.1
CiscoIos Xe Version16.4.2
CiscoIos Xe Version16.4.3
CiscoIos Xe Version16.5.1
CiscoIos Xe Version16.5.1a
CiscoIos Xe Version16.5.1b
CiscoIos Xe Version16.5.2
CiscoIos Xe Version16.5.3
CiscoIos Xe Version16.6.1
CiscoIos Xe Version16.6.2
CiscoIos Xe Version16.6.3
CiscoIos Xe Version16.7.1
CiscoIos Xe Version16.7.1a
CiscoIos Xe Version16.7.1b
CiscoIos Xe Version16.7.2
CiscoIos Xe Version16.8.1
CiscoIos Xe Version16.8.1a
CiscoIos Xe Version16.8.1b
CiscoIos Xe Version16.8.1c
CiscoIos Xe Version16.8.1d
CiscoIos Xe Version16.8.1s
CiscoIos Xe Version16.8.2
CiscoIos Xe Version16.9.1b
CiscoIos Xe Version16.9.1c
CiscoIos Xe Version16.9.1s
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.34% 0.562
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.