5.5
CVE-2019-1842
- EPSS 0.27%
- Veröffentlicht 05.06.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:37:30
- Quelle psirt@cisco.com
- CVE-Watchlists
- Unerledigt
A vulnerability in the Secure Shell (SSH) authentication function of Cisco IOS XR Software could allow an authenticated, remote attacker to successfully log in to an affected device using two distinct usernames. The vulnerability is due to a logic error that may occur when certain sequences of actions are processed during an SSH login event on the affected device. An attacker could exploit this vulnerability by initiating an SSH session to the device with a specific sequence that presents the two usernames. A successful exploit could result in logging data misrepresentation, user enumeration, or, in certain circumstances, a command authorization bypass. See the Details section for more information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Ios Xr Firmware Version6.1.2.tools
Cisco ≫ Asr 9001 Version-
Cisco ≫ Asr 9006 Version-
Cisco ≫ Asr 9010 Version-
Cisco ≫ Asr 9901 Version-
Cisco ≫ Asr 9904 Version-
Cisco ≫ Asr 9906 Version-
Cisco ≫ Asr 9910 Version-
Cisco ≫ Asr 9912 Version-
Cisco ≫ Asr 9922 Version-
Cisco ≫ Crs-1 16-slot Line Card Chassis Version-
Cisco ≫ Crs-1 16-slot Single-shelf System Version-
Cisco ≫ Crs-1 4-slot Single-shelf System Version-
Cisco ≫ Crs-1 8-slot Line Card Chassis Version-
Cisco ≫ Crs-1 8-slot Single-shelf System Version-
Cisco ≫ Crs-1 Fabric Card Chassis Version-
Cisco ≫ Crs-1 Line Card Chassis (dual) Version-
Cisco ≫ Crs-1 Line Card Chassis (multi) Version-
Cisco ≫ Crs-1 Multishelf System Version-
Cisco ≫ Crs-3 16-slot Single-shelf System Version-
Cisco ≫ Crs-3 4-slot Single-shelf System Version-
Cisco ≫ Crs-3 8-slot Single-shelf System Version-
Cisco ≫ Crs-3 Multishelf System Version-
Cisco ≫ Crs-8/s-b Crs Version-
Cisco ≫ Crs-8/scrs Version-
Cisco ≫ Crs-x 16-slot Single-shelf System Version-
Cisco ≫ Crs-x Multishelf System Version-
Cisco ≫ Ncs 6008-8-slot Chassis Version-
Cisco ≫ Network Convergence System 5508 Version-
Cisco ≫ Asr 9006 Version-
Cisco ≫ Asr 9010 Version-
Cisco ≫ Asr 9901 Version-
Cisco ≫ Asr 9904 Version-
Cisco ≫ Asr 9906 Version-
Cisco ≫ Asr 9910 Version-
Cisco ≫ Asr 9912 Version-
Cisco ≫ Asr 9922 Version-
Cisco ≫ Crs-1 16-slot Line Card Chassis Version-
Cisco ≫ Crs-1 16-slot Single-shelf System Version-
Cisco ≫ Crs-1 4-slot Single-shelf System Version-
Cisco ≫ Crs-1 8-slot Line Card Chassis Version-
Cisco ≫ Crs-1 8-slot Single-shelf System Version-
Cisco ≫ Crs-1 Fabric Card Chassis Version-
Cisco ≫ Crs-1 Line Card Chassis (dual) Version-
Cisco ≫ Crs-1 Line Card Chassis (multi) Version-
Cisco ≫ Crs-1 Multishelf System Version-
Cisco ≫ Crs-3 16-slot Single-shelf System Version-
Cisco ≫ Crs-3 4-slot Single-shelf System Version-
Cisco ≫ Crs-3 8-slot Single-shelf System Version-
Cisco ≫ Crs-3 Multishelf System Version-
Cisco ≫ Crs-8/s-b Crs Version-
Cisco ≫ Crs-8/scrs Version-
Cisco ≫ Crs-x 16-slot Single-shelf System Version-
Cisco ≫ Crs-x Multishelf System Version-
Cisco ≫ Ncs 6008-8-slot Chassis Version-
Cisco ≫ Network Convergence System 5508 Version-
Cisco ≫ Ios Xr Firmware Version6.1.3.tools
Cisco ≫ Asr 9001 Version-
Cisco ≫ Asr 9006 Version-
Cisco ≫ Asr 9010 Version-
Cisco ≫ Asr 9901 Version-
Cisco ≫ Asr 9904 Version-
Cisco ≫ Asr 9906 Version-
Cisco ≫ Asr 9910 Version-
Cisco ≫ Asr 9912 Version-
Cisco ≫ Asr 9922 Version-
Cisco ≫ Crs-1 16-slot Line Card Chassis Version-
Cisco ≫ Crs-1 16-slot Single-shelf System Version-
Cisco ≫ Crs-1 4-slot Single-shelf System Version-
Cisco ≫ Crs-1 8-slot Line Card Chassis Version-
Cisco ≫ Crs-1 8-slot Single-shelf System Version-
Cisco ≫ Crs-1 Fabric Card Chassis Version-
Cisco ≫ Crs-1 Line Card Chassis (dual) Version-
Cisco ≫ Crs-1 Line Card Chassis (multi) Version-
Cisco ≫ Crs-1 Multishelf System Version-
Cisco ≫ Crs-3 16-slot Single-shelf System Version-
Cisco ≫ Crs-3 4-slot Single-shelf System Version-
Cisco ≫ Crs-3 8-slot Single-shelf System Version-
Cisco ≫ Crs-3 Multishelf System Version-
Cisco ≫ Crs-8/s-b Crs Version-
Cisco ≫ Crs-8/scrs Version-
Cisco ≫ Crs-x 16-slot Single-shelf System Version-
Cisco ≫ Crs-x Multishelf System Version-
Cisco ≫ Ncs 6008-8-slot Chassis Version-
Cisco ≫ Network Convergence System 5508 Version-
Cisco ≫ Asr 9006 Version-
Cisco ≫ Asr 9010 Version-
Cisco ≫ Asr 9901 Version-
Cisco ≫ Asr 9904 Version-
Cisco ≫ Asr 9906 Version-
Cisco ≫ Asr 9910 Version-
Cisco ≫ Asr 9912 Version-
Cisco ≫ Asr 9922 Version-
Cisco ≫ Crs-1 16-slot Line Card Chassis Version-
Cisco ≫ Crs-1 16-slot Single-shelf System Version-
Cisco ≫ Crs-1 4-slot Single-shelf System Version-
Cisco ≫ Crs-1 8-slot Line Card Chassis Version-
Cisco ≫ Crs-1 8-slot Single-shelf System Version-
Cisco ≫ Crs-1 Fabric Card Chassis Version-
Cisco ≫ Crs-1 Line Card Chassis (dual) Version-
Cisco ≫ Crs-1 Line Card Chassis (multi) Version-
Cisco ≫ Crs-1 Multishelf System Version-
Cisco ≫ Crs-3 16-slot Single-shelf System Version-
Cisco ≫ Crs-3 4-slot Single-shelf System Version-
Cisco ≫ Crs-3 8-slot Single-shelf System Version-
Cisco ≫ Crs-3 Multishelf System Version-
Cisco ≫ Crs-8/s-b Crs Version-
Cisco ≫ Crs-8/scrs Version-
Cisco ≫ Crs-x 16-slot Single-shelf System Version-
Cisco ≫ Crs-x Multishelf System Version-
Cisco ≫ Ncs 6008-8-slot Chassis Version-
Cisco ≫ Network Convergence System 5508 Version-
Cisco ≫ Ios Xr Firmware Version6.2.3.tools
Cisco ≫ Asr 9001 Version-
Cisco ≫ Asr 9006 Version-
Cisco ≫ Asr 9010 Version-
Cisco ≫ Asr 9901 Version-
Cisco ≫ Asr 9904 Version-
Cisco ≫ Asr 9906 Version-
Cisco ≫ Asr 9910 Version-
Cisco ≫ Asr 9912 Version-
Cisco ≫ Asr 9922 Version-
Cisco ≫ Crs-1 16-slot Line Card Chassis Version-
Cisco ≫ Crs-1 16-slot Single-shelf System Version-
Cisco ≫ Crs-1 4-slot Single-shelf System Version-
Cisco ≫ Crs-1 8-slot Line Card Chassis Version-
Cisco ≫ Crs-1 8-slot Single-shelf System Version-
Cisco ≫ Crs-1 Fabric Card Chassis Version-
Cisco ≫ Crs-1 Line Card Chassis (dual) Version-
Cisco ≫ Crs-1 Line Card Chassis (multi) Version-
Cisco ≫ Crs-1 Multishelf System Version-
Cisco ≫ Crs-3 16-slot Single-shelf System Version-
Cisco ≫ Crs-3 4-slot Single-shelf System Version-
Cisco ≫ Crs-3 8-slot Single-shelf System Version-
Cisco ≫ Crs-3 Multishelf System Version-
Cisco ≫ Crs-8/s-b Crs Version-
Cisco ≫ Crs-8/scrs Version-
Cisco ≫ Crs-x 16-slot Single-shelf System Version-
Cisco ≫ Crs-x Multishelf System Version-
Cisco ≫ Ncs 6008-8-slot Chassis Version-
Cisco ≫ Network Convergence System 5508 Version-
Cisco ≫ Asr 9006 Version-
Cisco ≫ Asr 9010 Version-
Cisco ≫ Asr 9901 Version-
Cisco ≫ Asr 9904 Version-
Cisco ≫ Asr 9906 Version-
Cisco ≫ Asr 9910 Version-
Cisco ≫ Asr 9912 Version-
Cisco ≫ Asr 9922 Version-
Cisco ≫ Crs-1 16-slot Line Card Chassis Version-
Cisco ≫ Crs-1 16-slot Single-shelf System Version-
Cisco ≫ Crs-1 4-slot Single-shelf System Version-
Cisco ≫ Crs-1 8-slot Line Card Chassis Version-
Cisco ≫ Crs-1 8-slot Single-shelf System Version-
Cisco ≫ Crs-1 Fabric Card Chassis Version-
Cisco ≫ Crs-1 Line Card Chassis (dual) Version-
Cisco ≫ Crs-1 Line Card Chassis (multi) Version-
Cisco ≫ Crs-1 Multishelf System Version-
Cisco ≫ Crs-3 16-slot Single-shelf System Version-
Cisco ≫ Crs-3 4-slot Single-shelf System Version-
Cisco ≫ Crs-3 8-slot Single-shelf System Version-
Cisco ≫ Crs-3 Multishelf System Version-
Cisco ≫ Crs-8/s-b Crs Version-
Cisco ≫ Crs-8/scrs Version-
Cisco ≫ Crs-x 16-slot Single-shelf System Version-
Cisco ≫ Crs-x Multishelf System Version-
Cisco ≫ Ncs 6008-8-slot Chassis Version-
Cisco ≫ Network Convergence System 5508 Version-
Cisco ≫ Ios Xr Firmware Version6.4.2.tools
Cisco ≫ Asr 9001 Version-
Cisco ≫ Asr 9006 Version-
Cisco ≫ Asr 9010 Version-
Cisco ≫ Asr 9901 Version-
Cisco ≫ Asr 9904 Version-
Cisco ≫ Asr 9906 Version-
Cisco ≫ Asr 9910 Version-
Cisco ≫ Asr 9912 Version-
Cisco ≫ Asr 9922 Version-
Cisco ≫ Crs-1 16-slot Line Card Chassis Version-
Cisco ≫ Crs-1 16-slot Single-shelf System Version-
Cisco ≫ Crs-1 4-slot Single-shelf System Version-
Cisco ≫ Crs-1 8-slot Line Card Chassis Version-
Cisco ≫ Crs-1 8-slot Single-shelf System Version-
Cisco ≫ Crs-1 Fabric Card Chassis Version-
Cisco ≫ Crs-1 Line Card Chassis (dual) Version-
Cisco ≫ Crs-1 Line Card Chassis (multi) Version-
Cisco ≫ Crs-1 Multishelf System Version-
Cisco ≫ Crs-3 16-slot Single-shelf System Version-
Cisco ≫ Crs-3 4-slot Single-shelf System Version-
Cisco ≫ Crs-3 8-slot Single-shelf System Version-
Cisco ≫ Crs-3 Multishelf System Version-
Cisco ≫ Crs-8/s-b Crs Version-
Cisco ≫ Crs-8/scrs Version-
Cisco ≫ Crs-x 16-slot Single-shelf System Version-
Cisco ≫ Crs-x Multishelf System Version-
Cisco ≫ Ncs 6008-8-slot Chassis Version-
Cisco ≫ Network Convergence System 5508 Version-
Cisco ≫ Asr 9006 Version-
Cisco ≫ Asr 9010 Version-
Cisco ≫ Asr 9901 Version-
Cisco ≫ Asr 9904 Version-
Cisco ≫ Asr 9906 Version-
Cisco ≫ Asr 9910 Version-
Cisco ≫ Asr 9912 Version-
Cisco ≫ Asr 9922 Version-
Cisco ≫ Crs-1 16-slot Line Card Chassis Version-
Cisco ≫ Crs-1 16-slot Single-shelf System Version-
Cisco ≫ Crs-1 4-slot Single-shelf System Version-
Cisco ≫ Crs-1 8-slot Line Card Chassis Version-
Cisco ≫ Crs-1 8-slot Single-shelf System Version-
Cisco ≫ Crs-1 Fabric Card Chassis Version-
Cisco ≫ Crs-1 Line Card Chassis (dual) Version-
Cisco ≫ Crs-1 Line Card Chassis (multi) Version-
Cisco ≫ Crs-1 Multishelf System Version-
Cisco ≫ Crs-3 16-slot Single-shelf System Version-
Cisco ≫ Crs-3 4-slot Single-shelf System Version-
Cisco ≫ Crs-3 8-slot Single-shelf System Version-
Cisco ≫ Crs-3 Multishelf System Version-
Cisco ≫ Crs-8/s-b Crs Version-
Cisco ≫ Crs-8/scrs Version-
Cisco ≫ Crs-x 16-slot Single-shelf System Version-
Cisco ≫ Crs-x Multishelf System Version-
Cisco ≫ Ncs 6008-8-slot Chassis Version-
Cisco ≫ Network Convergence System 5508 Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.472 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
|
| nvd@nist.gov | 5.5 | 8 | 4.9 |
AV:N/AC:L/Au:S/C:P/I:P/A:N
|
| psirt@cisco.com | 5.4 | 2.8 | 2.5 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
|
CWE-285 Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.