CVE-2019-1757
MEDIUMCisco IOS and IOS XE - Unauthenticated Sensitive Data Exposure via Smart Call Home Certificate Validation
Title source: llmDescription
A vulnerability in the Cisco Smart Call Home feature of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data using an invalid certificate. The vulnerability is due to insufficient certificate validation by the affected software. An attacker could exploit this vulnerability by supplying a crafted certificate to an affected device. A successful exploit could allow the attacker to conduct man-in-the-middle attacks to decrypt confidential information on user connections to the affected software.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
x_refsource_cisco
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-call-home-cert
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/107617
Scores
CVSS v3
5.9
EPSS
0.0105
EPSS Percentile
59.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-295
Status
published
Products (50)
cisco/ios
2.3
cisco/ios
12.2\(6\)i1
cisco/ios
12.4\(25e\)jap1m
cisco/ios
12.4\(25e\)jap2
cisco/ios
12.4\(25e\)jap26
cisco/ios
12.4\(25e\)jaz1
cisco/ios
15.1\(2\)sg8a
cisco/ios
15.1\(3\)svg3d
cisco/ios
15.1\(3\)svi1b
cisco/ios
15.1\(3\)svm3
... and 40 more
Published
Mar 28, 2019
Tracked Since
Feb 18, 2026