Cisco IOS XE Software Receives Fix Against High-Severity Flaw

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
Cisco today released an updated version for its IOS XE software to patch a high severity cross-site request forgery (CSRF) vulnerability. Demo exploit code is available.
Hackers can leverage CSRF flaws to force the execution of unwanted actions in web pages or apps where the victim user has already authenticated.
These attacks can be deployed via a malicious link and the action is executed with the same privileges of the logged in user.

Multiple versions affected
Identified as CVE-2019-1904, the vulnerability affects outdated versions of Cisco IOS XE and has a severity score of 8.8 out of 10. It exists in the web-based user interface of the product.
... ...
 
  • +Reputation
Reactions: upnorth

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top