CVE-2019-12624
HIGHCisco IOS XE 3.0.xe-3.11.xe - Cross-Site Request Forgery in Web-Based Management Interface
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-12624. PoCs published by Mehmet Onder.
AI-analyzed exploit summary This is a CSRF exploit for Cisco Wireless Controller that adds an admin user via a malicious HTML form. It leverages lack of validity checks in HTTP requests to perform actions with administrative privileges.
Description
A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected device by using a web browser and with the privileges of the user.
Exploits (1)
This is a CSRF exploit for Cisco Wireless Controller that adds an admin user via a malicious HTML form. It leverages lack of validity checks in HTTP requests to perform actions with administrative privileges.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H