CVE-2019-1904 Details
Description
A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. If the user has administrative privileges, the attacker could alter the configuration, execute commands, or reload an affected device. This vulnerability affects Cisco devices that are running a vulnerable release of Cisco IOS XE Software with the HTTP Server feature enabled. The default state of the HTTP Server feature is version dependent.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 20, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco ios xe | 16.1.3 16.2.1 16.3.1 |
CPE
Remediation
| |
| cisco 4321 integrated services router | All versions |
CPE
Remediation
| |
| cisco 4331 integrated services router | All versions |
CPE
Remediation
| |
| cisco asr 1002-x | All versions |
CPE
Remediation
| |
| cisco 4431 integrated services router | All versions |
CPE
Remediation
| |
| cisco cloud services router 1000v | All versions |
CPE
Remediation
| |
| cisco asr 1000 series route processor (rp2) | All versions |
CPE
Remediation
| |
| cisco 4351 integrated services router | All versions |
CPE
Remediation
| |
| cisco 4451-x integrated services router | All versions |
CPE
Remediation
| |
| cisco asr 1002-hx | All versions |
CPE
Remediation
| |
| cisco asr 1001-x | All versions |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 18, 2021 | Modified Analysis | [email protected] |
| Oct 5, 2021 | CPE Deprecation Remap | [email protected] |
| Oct 5, 2021 | CPE Deprecation Remap | [email protected] |
| Oct 5, 2021 | CPE Deprecation Remap | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Jun 26, 2019 | Initial Analysis | [email protected] |