CVE-2019-1761

MEDIUM

Cisco IOS - Unauthenticated Information Disclosure via HSRPv2 Traffic

Title source: llm
STIX 2.1

Description

A vulnerability in the Hot Standby Router Protocol (HSRP) subsystem of Cisco IOS and IOS XE Software could allow an unauthenticated, adjacent attacker to receive potentially sensitive information from an affected device. The vulnerability is due to insufficient memory initialization. An attacker could exploit this vulnerability by receiving HSRPv2 traffic from an adjacent HSRP member. A successful exploit could allow the attacker to receive potentially sensitive information from the adjacent device.

References (2)

Core 2
Core References
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/107620

Scores

CVSS v3 4.3
EPSS 0.0063
EPSS Percentile 45.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-665
Status published
Products (50)
cisco/ios 12.2\(6\)i1
cisco/ios 12.2\(33\)cx
cisco/ios 12.2\(33\)cy
cisco/ios 12.2\(33\)cy1
cisco/ios 12.2\(33\)cy2
cisco/ios 12.2\(33\)ira
cisco/ios 12.2\(33\)irb
cisco/ios 12.2\(33\)irc
cisco/ios 12.2\(33\)ird
cisco/ios 12.2\(33\)ire
... and 40 more
Published Mar 28, 2019
Tracked Since Feb 18, 2026