A vulnerability in the Web Services Management Agent (WSMA) function of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary Cisco IOS commands as a privilege level 15 user. The vulnerability occurs because the affected software improperly sanitizes user-supplied input. An attacker could exploit this vulnerability by submitting crafted HTTP requests to the targeted application. A successful exploit could allow the attacker to execute arbitrary commands on the affected device.
2019-03-28T01:29:00.330
2024-11-21T04:37:17.687
Modified
CVSSv3.0: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | cisco | ios_xe | 3.2.0ja | Yes |
Operating System | cisco | ios_xe | 3.6.10e | Yes |
Operating System | cisco | ios_xe | 16.1.1 | Yes |
Operating System | cisco | ios_xe | 16.1.2 | Yes |
Operating System | cisco | ios_xe | 16.1.3 | Yes |
Operating System | cisco | ios_xe | 16.2.1 | Yes |
Operating System | cisco | ios_xe | 16.2.2 | Yes |
Operating System | cisco | ios_xe | 16.3.1 | Yes |
Operating System | cisco | ios_xe | 16.3.1a | Yes |
Operating System | cisco | ios_xe | 16.3.2 | Yes |
Operating System | cisco | ios_xe | 16.3.3 | Yes |
Operating System | cisco | ios_xe | 16.3.4 | Yes |
Operating System | cisco | ios_xe | 16.3.5 | Yes |
Operating System | cisco | ios_xe | 16.3.5b | Yes |
Operating System | cisco | ios_xe | 16.3.6 | Yes |
Operating System | cisco | ios_xe | 16.3.7 | Yes |
Operating System | cisco | ios_xe | 16.3.8 | Yes |
Operating System | cisco | ios_xe | 16.4.1 | Yes |
Operating System | cisco | ios_xe | 16.4.2 | Yes |
Operating System | cisco | ios_xe | 16.4.3 | Yes |
Operating System | cisco | ios_xe | 16.5.1 | Yes |
Operating System | cisco | ios_xe | 16.5.1a | Yes |
Operating System | cisco | ios_xe | 16.5.1b | Yes |
Operating System | cisco | ios_xe | 16.5.2 | Yes |
Operating System | cisco | ios_xe | 16.5.3 | Yes |
Operating System | cisco | ios_xe | 16.6.1 | Yes |
Operating System | cisco | ios_xe | 16.6.2 | Yes |
Operating System | cisco | ios_xe | 16.6.3 | Yes |
Operating System | cisco | ios_xe | 16.7.1 | Yes |
Operating System | cisco | ios_xe | 16.7.1a | Yes |
Operating System | cisco | ios_xe | 16.7.1b | Yes |
Operating System | cisco | ios_xe | 16.8.1 | Yes |
Operating System | cisco | ios_xe | 16.8.1a | Yes |
Operating System | cisco | ios_xe | 16.8.1b | Yes |
Operating System | cisco | ios_xe | 16.8.1c | Yes |
Operating System | cisco | ios_xe | 16.8.1d | Yes |
Operating System | cisco | ios_xe | 16.8.1e | Yes |
Operating System | cisco | ios_xe | 16.8.1s | Yes |