CVE Vulnerabilities

CVE-2019-1757

Improper Certificate Validation

Published: Mar 28, 2019 | Modified: Mar 04, 2024
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in the Cisco Smart Call Home feature of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data using an invalid certificate. The vulnerability is due to insufficient certificate validation by the affected software. An attacker could exploit this vulnerability by supplying a crafted certificate to an affected device. A successful exploit could allow the attacker to conduct man-in-the-middle attacks to decrypt confidential information on user connections to the affected software.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Ios Cisco 2.3 (including) 2.3 (including)
Ios Cisco 12.2(6)i1 (including) 12.2(6)i1 (including)
Ios Cisco 12.4(25e)jap1m (including) 12.4(25e)jap1m (including)
Ios Cisco 12.4(25e)jap2 (including) 12.4(25e)jap2 (including)
Ios Cisco 12.4(25e)jap26 (including) 12.4(25e)jap26 (including)
Ios Cisco 12.4(25e)jaz1 (including) 12.4(25e)jaz1 (including)
Ios Cisco 15.1(2)sg8a (including) 15.1(2)sg8a (including)
Ios Cisco 15.1(3)svg3d (including) 15.1(3)svg3d (including)
Ios Cisco 15.1(3)svi1b (including) 15.1(3)svi1b (including)
Ios Cisco 15.1(3)svm3 (including) 15.1(3)svm3 (including)
Ios Cisco 15.1(3)svn2 (including) 15.1(3)svn2 (including)
Ios Cisco 15.1(3)svo1 (including) 15.1(3)svo1 (including)
Ios Cisco 15.1(3)svo2 (including) 15.1(3)svo2 (including)
Ios Cisco 15.1(3)svp1 (including) 15.1(3)svp1 (including)
Ios Cisco 15.1(4)m12c (including) 15.1(4)m12c (including)
Ios Cisco 15.2(2)e4 (including) 15.2(2)e4 (including)
Ios Cisco 15.2(2)e5 (including) 15.2(2)e5 (including)
Ios Cisco 15.2(2)e5a (including) 15.2(2)e5a (including)
Ios Cisco 15.2(2)e5b (including) 15.2(2)e5b (including)
Ios Cisco 15.2(2)e6 (including) 15.2(2)e6 (including)
Ios Cisco 15.2(2)e7 (including) 15.2(2)e7 (including)
Ios Cisco 15.2(2)e7b (including) 15.2(2)e7b (including)
Ios Cisco 15.2(2)e8 (including) 15.2(2)e8 (including)
Ios Cisco 15.2(3)e4 (including) 15.2(3)e4 (including)
Ios Cisco 15.2(3)e5 (including) 15.2(3)e5 (including)
Ios Cisco 15.2(3)ea1 (including) 15.2(3)ea1 (including)
Ios Cisco 15.2(4)e2 (including) 15.2(4)e2 (including)
Ios Cisco 15.2(4)e3 (including) 15.2(4)e3 (including)
Ios Cisco 15.2(4)e4 (including) 15.2(4)e4 (including)
Ios Cisco 15.2(4)e5 (including) 15.2(4)e5 (including)
Ios Cisco 15.2(4)e5a (including) 15.2(4)e5a (including)
Ios Cisco 15.2(4)e6 (including) 15.2(4)e6 (including)
Ios Cisco 15.2(4)ea8 (including) 15.2(4)ea8 (including)
Ios Cisco 15.2(4)ea9 (including) 15.2(4)ea9 (including)
Ios Cisco 15.2(4)jaz1 (including) 15.2(4)jaz1 (including)
Ios Cisco 15.2(4)jn1 (including) 15.2(4)jn1 (including)
Ios Cisco 15.2(4a)ea5 (including) 15.2(4a)ea5 (including)
Ios Cisco 15.2(4m)e2 (including) 15.2(4m)e2 (including)
Ios Cisco 15.2(4m)e3 (including) 15.2(4m)e3 (including)
Ios Cisco 15.2(4n)e2 (including) 15.2(4n)e2 (including)
Ios Cisco 15.2(4o)e2 (including) 15.2(4o)e2 (including)
Ios Cisco 15.2(4o)e3 (including) 15.2(4o)e3 (including)
Ios Cisco 15.2(4p)e1 (including) 15.2(4p)e1 (including)
Ios Cisco 15.2(4q)e1 (including) 15.2(4q)e1 (including)
Ios Cisco 15.2(4s)e1 (including) 15.2(4s)e1 (including)
Ios Cisco 15.2(4s)e2 (including) 15.2(4s)e2 (including)
Ios Cisco 15.2(5)e (including) 15.2(5)e (including)
Ios Cisco 15.2(5)e1 (including) 15.2(5)e1 (including)
Ios Cisco 15.2(5)e2 (including) 15.2(5)e2 (including)
Ios Cisco 15.2(5)e2b (including) 15.2(5)e2b (including)
Ios Cisco 15.2(5)e2c (including) 15.2(5)e2c (including)
Ios Cisco 15.2(5)ea (including) 15.2(5)ea (including)
Ios Cisco 15.2(5)ex (including) 15.2(5)ex (including)
Ios Cisco 15.2(5a)e (including) 15.2(5a)e (including)
Ios Cisco 15.2(5a)e1 (including) 15.2(5a)e1 (including)
Ios Cisco 15.2(5b)e (including) 15.2(5b)e (including)
Ios Cisco 15.2(5c)e (including) 15.2(5c)e (including)
Ios Cisco 15.2(6)e (including) 15.2(6)e (including)
Ios Cisco 15.2(6)e0a (including) 15.2(6)e0a (including)
Ios Cisco 15.2(6)e0c (including) 15.2(6)e0c (including)
Ios Cisco 15.2(6)e1 (including) 15.2(6)e1 (including)
Ios Cisco 15.2(6)e1a (including) 15.2(6)e1a (including)
Ios Cisco 15.2(6)e1s (including) 15.2(6)e1s (including)
Ios Cisco 15.3(3)ja1n (including) 15.3(3)ja1n (including)
Ios Cisco 15.3(3)jd15 (including) 15.3(3)jd15 (including)
Ios Cisco 15.3(3)jda15 (including) 15.3(3)jda15 (including)
Ios Cisco 15.3(3)jf35 (including) 15.3(3)jf35 (including)
Ios Cisco 15.3(3)ji (including) 15.3(3)ji (including)
Ios Cisco 15.3(3)ji2 (including) 15.3(3)ji2 (including)
Ios Cisco 15.3(3)jn1 (including) 15.3(3)jn1 (including)
Ios Cisco 15.3(3)jn2 (including) 15.3(3)jn2 (including)
Ios Cisco 15.5(3)s1 (including) 15.5(3)s1 (including)
Ios Cisco 15.5(3)s1a (including) 15.5(3)s1a (including)
Ios Cisco 15.5(3)s2 (including) 15.5(3)s2 (including)
Ios Cisco 15.5(3)s3 (including) 15.5(3)s3 (including)
Ios Cisco 15.5(3)s4 (including) 15.5(3)s4 (including)
Ios Cisco 15.5(3)s5 (including) 15.5(3)s5 (including)
Ios Cisco 15.5(3)s6 (including) 15.5(3)s6 (including)
Ios Cisco 15.5(3)s6a (including) 15.5(3)s6a (including)
Ios Cisco 15.5(3)s6b (including) 15.5(3)s6b (including)
Ios Cisco 15.5(3)s7 (including) 15.5(3)s7 (including)
Ios Cisco 15.6(1)s (including) 15.6(1)s (including)
Ios Cisco 15.6(1)s1 (including) 15.6(1)s1 (including)
Ios Cisco 15.6(1)s2 (including) 15.6(1)s2 (including)
Ios Cisco 15.6(1)s3 (including) 15.6(1)s3 (including)
Ios Cisco 15.6(1)s4 (including) 15.6(1)s4 (including)
Ios Cisco 15.6(1)sn (including) 15.6(1)sn (including)
Ios Cisco 15.6(1)sn1 (including) 15.6(1)sn1 (including)
Ios Cisco 15.6(1)sn2 (including) 15.6(1)sn2 (including)
Ios Cisco 15.6(1)sn3 (including) 15.6(1)sn3 (including)
Ios Cisco 15.6(1)t (including) 15.6(1)t (including)
Ios Cisco 15.6(1)t0a (including) 15.6(1)t0a (including)
Ios Cisco 15.6(1)t1 (including) 15.6(1)t1 (including)
Ios Cisco 15.6(1)t2 (including) 15.6(1)t2 (including)
Ios Cisco 15.6(1)t3 (including) 15.6(1)t3 (including)
Ios Cisco 15.6(2)s (including) 15.6(2)s (including)
Ios Cisco 15.6(2)s1 (including) 15.6(2)s1 (including)
Ios Cisco 15.6(2)s2 (including) 15.6(2)s2 (including)
Ios Cisco 15.6(2)s3 (including) 15.6(2)s3 (including)
Ios Cisco 15.6(2)s4 (including) 15.6(2)s4 (including)
Ios Cisco 15.6(2)sn (including) 15.6(2)sn (including)
Ios Cisco 15.6(2)sp (including) 15.6(2)sp (including)
Ios Cisco 15.6(2)sp1 (including) 15.6(2)sp1 (including)
Ios Cisco 15.6(2)sp2 (including) 15.6(2)sp2 (including)
Ios Cisco 15.6(2)sp3 (including) 15.6(2)sp3 (including)
Ios Cisco 15.6(2)sp3b (including) 15.6(2)sp3b (including)
Ios Cisco 15.6(2)sp4 (including) 15.6(2)sp4 (including)
Ios Cisco 15.6(2)t (including) 15.6(2)t (including)
Ios Cisco 15.6(2)t0a (including) 15.6(2)t0a (including)
Ios Cisco 15.6(2)t1 (including) 15.6(2)t1 (including)
Ios Cisco 15.6(2)t2 (including) 15.6(2)t2 (including)
Ios Cisco 15.6(2)t3 (including) 15.6(2)t3 (including)
Ios Cisco 15.6(3)m (including) 15.6(3)m (including)
Ios Cisco 15.6(3)m0a (including) 15.6(3)m0a (including)
Ios Cisco 15.6(3)m1 (including) 15.6(3)m1 (including)
Ios Cisco 15.6(3)m1a (including) 15.6(3)m1a (including)
Ios Cisco 15.6(3)m1b (including) 15.6(3)m1b (including)
Ios Cisco 15.6(3)m2 (including) 15.6(3)m2 (including)
Ios Cisco 15.6(3)m2a (including) 15.6(3)m2a (including)
Ios Cisco 15.6(3)m3 (including) 15.6(3)m3 (including)
Ios Cisco 15.6(3)m3a (including) 15.6(3)m3a (including)
Ios Cisco 15.6(3)m4 (including) 15.6(3)m4 (including)
Ios Cisco 15.6(3)sn (including) 15.6(3)sn (including)
Ios Cisco 15.6(4)sn (including) 15.6(4)sn (including)
Ios Cisco 15.6(5)sn (including) 15.6(5)sn (including)
Ios Cisco 15.6(6)sn (including) 15.6(6)sn (including)
Ios Cisco 15.6(7)sn (including) 15.6(7)sn (including)
Ios Cisco 15.7(3)m (including) 15.7(3)m (including)
Ios Cisco 15.7(3)m0a (including) 15.7(3)m0a (including)
Ios Cisco 15.7(3)m1 (including) 15.7(3)m1 (including)
Ios Cisco 15.7(3)m2 (including) 15.7(3)m2 (including)
Ios_xe Cisco 3.6.4e (including) 3.6.4e (including)
Ios_xe Cisco 3.6.5ae (including) 3.6.5ae (including)
Ios_xe Cisco 3.6.5be (including) 3.6.5be (including)
Ios_xe Cisco 3.6.5e (including) 3.6.5e (including)
Ios_xe Cisco 3.6.6e (including) 3.6.6e (including)
Ios_xe Cisco 3.6.7ae (including) 3.6.7ae (including)
Ios_xe Cisco 3.6.7be (including) 3.6.7be (including)
Ios_xe Cisco 3.6.7e (including) 3.6.7e (including)
Ios_xe Cisco 3.6.8e (including) 3.6.8e (including)
Ios_xe Cisco 3.7.4e (including) 3.7.4e (including)
Ios_xe Cisco 3.7.5e (including) 3.7.5e (including)
Ios_xe Cisco 3.8.2e (including) 3.8.2e (including)
Ios_xe Cisco 3.8.3e (including) 3.8.3e (including)
Ios_xe Cisco 3.8.4e (including) 3.8.4e (including)
Ios_xe Cisco 3.8.5ae (including) 3.8.5ae (including)
Ios_xe Cisco 3.8.5e (including) 3.8.5e (including)
Ios_xe Cisco 3.8.6e (including) 3.8.6e (including)
Ios_xe Cisco 3.9.0e (including) 3.9.0e (including)
Ios_xe Cisco 3.9.1e (including) 3.9.1e (including)
Ios_xe Cisco 3.9.2be (including) 3.9.2be (including)
Ios_xe Cisco 3.9.2e (including) 3.9.2e (including)
Ios_xe Cisco 3.10.0ce (including) 3.10.0ce (including)
Ios_xe Cisco 3.10.0e (including) 3.10.0e (including)
Ios_xe Cisco 3.10.1ae (including) 3.10.1ae (including)
Ios_xe Cisco 3.10.1e (including) 3.10.1e (including)
Ios_xe Cisco 3.10.1se (including) 3.10.1se (including)
Ios_xe Cisco 3.16.1as (including) 3.16.1as (including)
Ios_xe Cisco 3.16.1s (including) 3.16.1s (including)
Ios_xe Cisco 3.16.2as (including) 3.16.2as (including)
Ios_xe Cisco 3.16.2bs (including) 3.16.2bs (including)
Ios_xe Cisco 3.16.2s (including) 3.16.2s (including)
Ios_xe Cisco 3.16.3as (including) 3.16.3as (including)
Ios_xe Cisco 3.16.3s (including) 3.16.3s (including)
Ios_xe Cisco 3.16.4as (including) 3.16.4as (including)
Ios_xe Cisco 3.16.4bs (including) 3.16.4bs (including)
Ios_xe Cisco 3.16.4cs (including) 3.16.4cs (including)
Ios_xe Cisco 3.16.4ds (including) 3.16.4ds (including)
Ios_xe Cisco 3.16.4es (including) 3.16.4es (including)
Ios_xe Cisco 3.16.4gs (including) 3.16.4gs (including)
Ios_xe Cisco 3.16.4s (including) 3.16.4s (including)
Ios_xe Cisco 3.16.5as (including) 3.16.5as (including)
Ios_xe Cisco 3.16.5bs (including) 3.16.5bs (including)
Ios_xe Cisco 3.16.5s (including) 3.16.5s (including)
Ios_xe Cisco 3.16.6bs (including) 3.16.6bs (including)
Ios_xe Cisco 3.16.6s (including) 3.16.6s (including)
Ios_xe Cisco 3.16.7as (including) 3.16.7as (including)
Ios_xe Cisco 3.16.7bs (including) 3.16.7bs (including)
Ios_xe Cisco 3.16.7s (including) 3.16.7s (including)
Ios_xe Cisco 3.17.0s (including) 3.17.0s (including)
Ios_xe Cisco 3.17.1as (including) 3.17.1as (including)
Ios_xe Cisco 3.17.1s (including) 3.17.1s (including)
Ios_xe Cisco 3.17.3s (including) 3.17.3s (including)
Ios_xe Cisco 3.17.4s (including) 3.17.4s (including)
Ios_xe Cisco 3.18.0as (including) 3.18.0as (including)
Ios_xe Cisco 3.18.0s (including) 3.18.0s (including)
Ios_xe Cisco 3.18.0sp (including) 3.18.0sp (including)
Ios_xe Cisco 3.18.1asp (including) 3.18.1asp (including)
Ios_xe Cisco 3.18.1bsp (including) 3.18.1bsp (including)
Ios_xe Cisco 3.18.1csp (including) 3.18.1csp (including)
Ios_xe Cisco 3.18.1gsp (including) 3.18.1gsp (including)
Ios_xe Cisco 3.18.1hsp (including) 3.18.1hsp (including)
Ios_xe Cisco 3.18.1isp (including) 3.18.1isp (including)
Ios_xe Cisco 3.18.1s (including) 3.18.1s (including)
Ios_xe Cisco 3.18.1sp (including) 3.18.1sp (including)
Ios_xe Cisco 3.18.2asp (including) 3.18.2asp (including)
Ios_xe Cisco 3.18.2s (including) 3.18.2s (including)
Ios_xe Cisco 3.18.2sp (including) 3.18.2sp (including)
Ios_xe Cisco 3.18.3asp (including) 3.18.3asp (including)
Ios_xe Cisco 3.18.3bsp (including) 3.18.3bsp (including)
Ios_xe Cisco 3.18.3s (including) 3.18.3s (including)
Ios_xe Cisco 3.18.3sp (including) 3.18.3sp (including)
Ios_xe Cisco 3.18.4s (including) 3.18.4s (including)
Ios_xe Cisco 3.18.4sp (including) 3.18.4sp (including)
Ios_xe Cisco 16.2.1 (including) 16.2.1 (including)
Ios_xe Cisco 16.2.2 (including) 16.2.2 (including)
Ios_xe Cisco 16.3.1 (including) 16.3.1 (including)
Ios_xe Cisco 16.3.1a (including) 16.3.1a (including)
Ios_xe Cisco 16.3.2 (including) 16.3.2 (including)
Ios_xe Cisco 16.3.3 (including) 16.3.3 (including)
Ios_xe Cisco 16.3.4 (including) 16.3.4 (including)
Ios_xe Cisco 16.3.5 (including) 16.3.5 (including)
Ios_xe Cisco 16.3.5b (including) 16.3.5b (including)
Ios_xe Cisco 16.3.6 (including) 16.3.6 (including)
Ios_xe Cisco 16.4.1 (including) 16.4.1 (including)
Ios_xe Cisco 16.4.2 (including) 16.4.2 (including)
Ios_xe Cisco 16.4.3 (including) 16.4.3 (including)
Ios_xe Cisco 16.5.1 (including) 16.5.1 (including)
Ios_xe Cisco 16.5.1a (including) 16.5.1a (including)
Ios_xe Cisco 16.5.1b (including) 16.5.1b (including)
Ios_xe Cisco 16.5.2 (including) 16.5.2 (including)
Ios_xe Cisco 16.5.3 (including) 16.5.3 (including)
Ios_xe Cisco 16.6.1 (including) 16.6.1 (including)
Ios_xe Cisco 16.6.2 (including) 16.6.2 (including)
Ios_xe Cisco 16.6.3 (including) 16.6.3 (including)
Ios_xe Cisco 16.7.1 (including) 16.7.1 (including)
Ios_xe Cisco 16.7.1a (including) 16.7.1a (including)
Ios_xe Cisco 16.7.1b (including) 16.7.1b (including)
Ios_xe Cisco 16.7.2 (including) 16.7.2 (including)
Ios_xe Cisco 16.8.1 (including) 16.8.1 (including)
Ios_xe Cisco 16.8.1a (including) 16.8.1a (including)
Ios_xe Cisco 16.8.1b (including) 16.8.1b (including)
Ios_xe Cisco 16.8.1c (including) 16.8.1c (including)
Ios_xe Cisco 16.8.1d (including) 16.8.1d (including)
Ios_xe Cisco 16.8.1s (including) 16.8.1s (including)
Ios_xe Cisco 16.8.2 (including) 16.8.2 (including)
Ios_xe Cisco 16.9.1b (including) 16.9.1b (including)
Ios_xe Cisco 16.9.1c (including) 16.9.1c (including)
Ios_xe Cisco 16.9.1s (including) 16.9.1s (including)

Potential Mitigations

References