← All CVEs

CVE-2019-12624

high · 8.8

A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected device by using a web browser and with the privileges of the user.

8.8
CVSS
18.2%
EPSS (exploit prob.)
97th
EPSS percentile
2019-08-21
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-352

Affected products

VendorProductAffected versions
ciscoios_xe>= 3.0.xe, <= 3.11.xe
cisco5760_wireless_lan_controllerall versions
ciscocatalyst_3650-12x48uqall versions
ciscocatalyst_3650-12x48urall versions
ciscocatalyst_3650-12x48uzall versions
ciscocatalyst_3650-24pdall versions
ciscocatalyst_3650-24pdmall versions
ciscocatalyst_3650-48fqall versions
ciscocatalyst_3650-48fqmall versions
ciscocatalyst_3650-8x24uqall versions
ciscocatalyst_3850-12x48uall versions
ciscocatalyst_3850-24uall versions
ciscocatalyst_3850-24xsall versions
ciscocatalyst_3850-24xuall versions
ciscocatalyst_3850-48uall versions
ciscocatalyst_3850-48xsall versions
ciscocatalyst_3850-nm-2-40gall versions
ciscocatalyst_3850-nm-8-10gall versions
ciscocatalyst_4500e_supervisor_engine_8-eall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-12624