CVE-2019-1762 Details
Description
A vulnerability in the Secure Storage feature of Cisco IOS and IOS XE Software could allow an authenticated, local attacker to access sensitive system information on an affected device. The vulnerability is due to improper memory operations performed at encryption time, when affected software handles configuration updates. An attacker could exploit this vulnerability by retrieving the contents of specific memory locations of an affected device. A successful exploit could result in the disclosure of keying materials that are part of the device configuration, which can be used to recover critical system information.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-info | CVE | PatchVendor Advisory |
| http://www.securityfocus.com/bid/107594 | CVE | Third Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190327-info | [email protected] | PatchVendor Advisory |
| http://www.securityfocus.com/bid/107594 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco ios | 12.2(6)i1 15.1(2)sg8a 15.1(3)svg3d 15.1(3)svi1b 15.1(3)svm3 15.1(3)svn2 15.1(3)svo1 15.1(3)svo2 15.1(3)svp1 15.1(4)m12c 15.2(3)ea1 15.2(4)jn1 15.2(4a)ea5 15.3(3)ja1n 15.3(3)jf35 15.3(3)ji2 15.3(3)jn1 15.3(3)jn2 15.6(2)sp3b 15.6(3)m1 15.6(3)m1a 15.6(3)m1b 15.6(3)m2 15.6(3)m2a 15.6(3)m3 15.6(3)m3a 15.6(3)m4 15.6(3.1)m 15.7(3)m 15.7(3)m0a 15.7(3)m1 |
CPE
Remediation
| |
| cisco ios xe | 16.6.1 16.6.2 16.6.3 16.6.4 16.6.4a 16.6.4s 16.7.1 16.7.1a 16.7.1b 16.7.2 16.7.3 16.7.4 16.8.1 16.8.1a 16.8.1b 16.8.1c 16.8.1d 16.8.1e 16.8.1s 16.8.2 16.9.1 16.9.1a 16.9.1b 16.9.1c 16.9.1d 16.9.1s 16.9.2 16.9.2a |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Apr 2, 2019 | Initial Analysis | [email protected] |
| Mar 28, 2019 | CVE Modified | [email protected] |