Back

HIGH

Cisco IOS XE Software Arbitrary File Upload Vulnerability

Published Mar 27, 2019

Description

A vulnerability in the web UI framework of Cisco IOS XE Software could allow an authenticated, remote attacker to make unauthorized changes to the filesystem of the affected device. The vulnerability is due to improper input validation. An attacker could exploit this vulnerability by crafting a malicious file and uploading it to the device. An exploit could allow the attacker to gain elevated privileges on the affected device.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner cisco
Published Mar 27, 2019
Updated Nov 20, 2024
Reserved Dec 6, 2018

CISA Vulnrichment

Updated Nov 20, 2024

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner cisco
Published Mar 27, 2019
Updated Nov 20, 2024

GitHub

No data