ID

VAR-201909-0180


CVE

CVE-2019-12667


TITLE

Cisco IOS XE Software cross-site scripting vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2019-010295

DESCRIPTION

A vulnerability in the web framework code of Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of the affected software. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected software. An attacker could exploit this vulnerability by convincing a user of the web interface to access a malicious link or by intercepting a user request for the affected web interface and injecting malicious code into the request. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected web interface or allow the attacker to access sensitive browser-based information

Trust: 2.25

sources: NVD: CVE-2019-12667 // JVNDB: JVNDB-2019-010295 // CNVD: CNVD-2019-33476 // VULHUB: VHN-144436

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2019-33476

AFFECTED PRODUCTS

vendor:ciscomodel:ios xescope: - version: -

Trust: 1.4

vendor:ciscomodel:ios xescope:ltversion:16.6.5

Trust: 1.0

vendor:ciscomodel:ios xescope:gteversion:16.7.1

Trust: 1.0

vendor:ciscomodel:ios xescope:ltversion:16.9.2

Trust: 1.0

vendor:ciscomodel:ios xescope:gteversion:16.1.1

Trust: 1.0

vendor:ciscomodel:ios xescope:eqversion:16.1.1

Trust: 0.6

vendor:ciscomodel:ios xescope:eqversion:16.5.1

Trust: 0.6

vendor:ciscomodel:ios xescope:eqversion:16.3.4

Trust: 0.6

vendor:ciscomodel:ios xescope:eqversion:16.4.2

Trust: 0.6

vendor:ciscomodel:ios xescope:eqversion:16.5.1b

Trust: 0.6

sources: CNVD: CNVD-2019-33476 // JVNDB: JVNDB-2019-010295 // CNNVD: CNNVD-201909-1156 // NVD: CVE-2019-12667

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-12667
value: MEDIUM

Trust: 1.0

ykramarz@cisco.com: CVE-2019-12667
value: MEDIUM

Trust: 1.0

NVD: CVE-2019-12667
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2019-33476
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201909-1156
value: MEDIUM

Trust: 0.6

VULHUB: VHN-144436
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2019-12667
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2019-33476
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-144436
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-12667
baseSeverity: MEDIUM
baseScore: 4.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 1.7
impactScore: 2.7
version: 3.1

Trust: 1.0

ykramarz@cisco.com: CVE-2019-12667
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.3
impactScore: 2.7
version: 3.0

Trust: 1.0

NVD: CVE-2019-12667
baseSeverity: MEDIUM
baseScore: 4.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2019-33476 // VULHUB: VHN-144436 // JVNDB: JVNDB-2019-010295 // CNNVD: CNNVD-201909-1156 // NVD: CVE-2019-12667 // NVD: CVE-2019-12667

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-144436 // JVNDB: JVNDB-2019-010295 // NVD: CVE-2019-12667

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201909-1156

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201909-1156

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-010295

PATCH

title:cisco-sa-20190925-xssurl:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190925-xss

Trust: 0.8

title:Patch for Cisco IOS XE Cross-Site Scripting Vulnerability (CNVD-2019-33476)url:https://www.cnvd.org.cn/patchInfo/show/182385

Trust: 0.6

title:Cisco IOS XE Fixes for cross-site scripting vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=98570

Trust: 0.6

sources: CNVD: CNVD-2019-33476 // JVNDB: JVNDB-2019-010295 // CNNVD: CNNVD-201909-1156

EXTERNAL IDS

db:NVDid:CVE-2019-12667

Trust: 3.1

db:JVNDBid:JVNDB-2019-010295

Trust: 0.8

db:CNNVDid:CNNVD-201909-1156

Trust: 0.7

db:CNVDid:CNVD-2019-33476

Trust: 0.6

db:AUSCERTid:ESB-2019.3615.2

Trust: 0.6

db:AUSCERTid:ESB-2019.3615

Trust: 0.6

db:VULHUBid:VHN-144436

Trust: 0.1

sources: CNVD: CNVD-2019-33476 // VULHUB: VHN-144436 // JVNDB: JVNDB-2019-010295 // CNNVD: CNNVD-201909-1156 // NVD: CVE-2019-12667

REFERENCES

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20190925-xss

Trust: 2.3

url:https://nvd.nist.gov/vuln/detail/cve-2019-12667

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-12667

Trust: 0.8

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20190925-webui-cmd-injection

Trust: 0.6

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20190925-vman-cmd-injection

Trust: 0.6

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20190925-utd

Trust: 0.6

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20190925-ctspac-dos

Trust: 0.6

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20190925-rawtcp-dos

Trust: 0.6

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20190925-dt

Trust: 0.6

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20190925-sip-alg

Trust: 0.6

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20190925-isdn-data-leak

Trust: 0.6

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20190925-iox-gs

Trust: 0.6

url:httpserv-dos

Trust: 0.6

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20190925-iosxe-fsdos

Trust: 0.6

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20190925-ftp

Trust: 0.6

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20190925-iosxe-digsig-bypass

Trust: 0.6

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20190925-iosxe-ctbypass

Trust: 0.6

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20190925-iosxe-codeexec

Trust: 0.6

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20190925-awr

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2019.3615.2/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2019.3615/

Trust: 0.6

url:https://vigilance.fr/vulnerability/cisco-ios-xe-cross-site-scripting-30448

Trust: 0.6

sources: CNVD: CNVD-2019-33476 // VULHUB: VHN-144436 // JVNDB: JVNDB-2019-010295 // CNNVD: CNNVD-201909-1156 // NVD: CVE-2019-12667

CREDITS

Nishith Sinha .

Trust: 0.6

sources: CNNVD: CNNVD-201909-1156

SOURCES

db:CNVDid:CNVD-2019-33476
db:VULHUBid:VHN-144436
db:JVNDBid:JVNDB-2019-010295
db:CNNVDid:CNNVD-201909-1156
db:NVDid:CVE-2019-12667

LAST UPDATE DATE

2024-11-23T21:36:54.667000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-33476date:2019-09-27T00:00:00
db:VULHUBid:VHN-144436date:2019-10-09T00:00:00
db:JVNDBid:JVNDB-2019-010295date:2019-10-10T00:00:00
db:CNNVDid:CNNVD-201909-1156date:2019-10-17T00:00:00
db:NVDid:CVE-2019-12667date:2024-11-21T04:23:18.900

SOURCES RELEASE DATE

db:CNVDid:CNVD-2019-33476date:2019-09-27T00:00:00
db:VULHUBid:VHN-144436date:2019-09-25T00:00:00
db:JVNDBid:JVNDB-2019-010295date:2019-10-10T00:00:00
db:CNNVDid:CNNVD-201909-1156date:2019-09-25T00:00:00
db:NVDid:CVE-2019-12667date:2019-09-25T21:15:11.517