Логотип exploitDog
bind:CVE-2019-1753
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-1753

Количество 3

Количество 3

nvd логотип

CVE-2019-1753

почти 7 лет назад

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote attacker to run privileged Cisco IOS commands by using the web UI. The vulnerability is due to a failure to validate and sanitize input in Web Services Management Agent (WSMA) functions. An attacker could exploit this vulnerability by submitting a malicious payload to the affected device's web UI. A successful exploit could allow the lower-privileged attacker to execute arbitrary commands with higher privileges on the affected device.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-c7q8-hx63-756r

больше 3 лет назад

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote attacker to run privileged Cisco IOS commands by using the web UI. The vulnerability is due to a failure to validate and sanitize input in Web Services Management Agent (WSMA) functions. An attacker could exploit this vulnerability by submitting a malicious payload to the affected device's web UI. A successful exploit could allow the lower-privileged attacker to execute arbitrary commands with higher privileges on the affected device.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2019-01329

почти 7 лет назад

Уязвимость компонента Web Services Management Agent веб-интерфейса операционной системы Cisco IOS XE, позволяющая нарушителю выполнять команды с повышенными привилегиями

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-1753

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote attacker to run privileged Cisco IOS commands by using the web UI. The vulnerability is due to a failure to validate and sanitize input in Web Services Management Agent (WSMA) functions. An attacker could exploit this vulnerability by submitting a malicious payload to the affected device's web UI. A successful exploit could allow the lower-privileged attacker to execute arbitrary commands with higher privileges on the affected device.

CVSS3: 8.8
1%
Низкий
почти 7 лет назад
github логотип
GHSA-c7q8-hx63-756r

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote attacker to run privileged Cisco IOS commands by using the web UI. The vulnerability is due to a failure to validate and sanitize input in Web Services Management Agent (WSMA) functions. An attacker could exploit this vulnerability by submitting a malicious payload to the affected device's web UI. A successful exploit could allow the lower-privileged attacker to execute arbitrary commands with higher privileges on the affected device.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
fstec логотип
BDU:2019-01329

Уязвимость компонента Web Services Management Agent веб-интерфейса операционной системы Cisco IOS XE, позволяющая нарушителю выполнять команды с повышенными привилегиями

CVSS3: 8.8
1%
Низкий
почти 7 лет назад

Уязвимостей на страницу