CVE-2019-1950
Description
A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, local attacker to gain unauthorized access to an affected device. The vulnerability is due to the existence of default credentials within the default configuration of an affected device. An attacker who has access to an affected device could log in with elevated privileges. A successful exploit could allow the attacker to take complete control of the device. This vulnerability affects Cisco devices that are running Cisco IOS XE SD-WAN Software releases 16.11 and earlier.
Risk Information
Base Score
8.4
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.385
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Cisco IOS XE SD-WAN Software Default Credentials Vulnerability For Cisco IOS XE SD-WAN Software | NCM |
| Initialization of a Resource with an Insecure Default Vulnerability (CVE-2019-1950) | NCM |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-1706092 | Security Update for Cisco IOS XE SD-WAN Software sdwan-20.6(999.751) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234