8.4

CVE-2019-1950

A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, local attacker to gain unauthorized access to an affected device. The vulnerability is due to the existence of default credentials within the default configuration of an affected device. An attacker who has access to an affected device could log in with elevated privileges. A successful exploit could allow the attacker to take complete control of the device. This vulnerability affects Cisco devices that are running Cisco IOS XE SD-WAN Software releases 16.11 and earlier.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoIos Xe Version <= 16.11
   Cisco1100-4p Integrated Services Router Version-
   Cisco1100-8p Integrated Services Router Version-
   Cisco1101-4p Integrated Services Router Version-
   Cisco1109-2p Integrated Services Router Version-
   Cisco1109-4p Integrated Services Router Version-
   Cisco1111x-8p Integrated Services Router Version-
   Cisco4221 Integrated Services Router Version-
   Cisco4331 Integrated Services Router Version-
   Cisco4431 Integrated Services Router Version-
   Cisco4461 Integrated Services Router Version-
   CiscoAsr 1000-x Version-
   CiscoAsr 1001-hx Version-
   CiscoAsr 1002-hx Version-
   CiscoAsr 1002-x Version-
   CiscoAsr 1004 Version-
   CiscoAsr 1006 Version-
   CiscoAsr 1006-x Version-
   CiscoAsr 1009-x Version-
   CiscoAsr 1013 Version-
   CiscoCsr1000v Version-
   CiscoIr1101 Version-
   CiscoNexus 56128p Version-
   CiscoNexus 5624q Version-
   CiscoNexus 5648q Version-
   CiscoNexus 5672up Version-
   CiscoNexus 5672up-16g Version-
   CiscoNexus 5696q Version-
   CiscoUcs-e1120d-m3 Version-
   CiscoUcs-e140s-m2 Version-
   CiscoUcs-e160d-m2 Version-
   CiscoUcs-e160s-m3 Version-
   CiscoUcs-e180d-m2 Version-
   CiscoUcs-e180d-m3 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.59
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
psirt@cisco.com 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-1188 Initialization of a Resource with an Insecure Default

The product initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure.