peter bassill · operator
$ cve CVE-2019-12624 JSON

CVE-2019-12624 EXPLOIT

8.8
HIGH · CVSS 3.0 · EPSS 18.2% (pctl 97)

Patch early

A public exploit exists.

Description

A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected device by using a web browser and with the privileges of the user.

Scoring

CVSS8.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS18.19% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2019-08-21
Last modified2026-06-17

Affected (19)

VendorProduct
cisco5760 wireless lan controller
ciscocatalyst 3650-12x48uq
ciscocatalyst 3650-12x48ur
ciscocatalyst 3650-12x48uz
ciscocatalyst 3650-24pd
ciscocatalyst 3650-24pdm
ciscocatalyst 3650-48fq
ciscocatalyst 3650-48fqm
ciscocatalyst 3650-8x24uq
ciscocatalyst 3850-12x48u
ciscocatalyst 3850-24u
ciscocatalyst 3850-24xs
ciscocatalyst 3850-24xu
ciscocatalyst 3850-48u
ciscocatalyst 3850-48xs
ciscocatalyst 3850-nm-2-40g
ciscocatalyst 3850-nm-8-10g
ciscocatalyst 4500e supervisor engine 8-e
ciscoios xe

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD