CVE-2019-12624
high · 8.8A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected device by using a web browser and with the privileges of the user.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| cisco | ios_xe | >= 3.0.xe, <= 3.11.xe |
| cisco | 5760_wireless_lan_controller | all versions |
| cisco | catalyst_3650-12x48uq | all versions |
| cisco | catalyst_3650-12x48ur | all versions |
| cisco | catalyst_3650-12x48uz | all versions |
| cisco | catalyst_3650-24pd | all versions |
| cisco | catalyst_3650-24pdm | all versions |
| cisco | catalyst_3650-48fq | all versions |
| cisco | catalyst_3650-48fqm | all versions |
| cisco | catalyst_3650-8x24uq | all versions |
| cisco | catalyst_3850-12x48u | all versions |
| cisco | catalyst_3850-24u | all versions |
| cisco | catalyst_3850-24xs | all versions |
| cisco | catalyst_3850-24xu | all versions |
| cisco | catalyst_3850-48u | all versions |
| cisco | catalyst_3850-48xs | all versions |
| cisco | catalyst_3850-nm-2-40g | all versions |
| cisco | catalyst_3850-nm-8-10g | all versions |
| cisco | catalyst_4500e_supervisor_engine_8-e | all versions |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-12624