CVE-2019-12651

HIGH

Cisco IOS XE - Authenticated Remote Command Execution via Web UI

Title source: llm
STIX 2.1

Description

Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabilities, see the Details section of this advisory.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0254
EPSS Percentile 83.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-77 CWE-78
Status published
Products (3)
cisco/cloud_services_router_1000v_firmware 17.1.1
cisco/integrated_services_virtual_router_firmware 16.6.5
cisco/ios 16.11.1
Published Sep 25, 2019
Tracked Since Feb 18, 2026