CVE-2019-1762

A vulnerability in the Secure Storage feature of Cisco IOS and IOS XE Software could allow an authenticated, local attacker to access sensitive system information on an affected device. The vulnerability is due to improper memory operations performed at encryption time, when affected software handles configuration updates. An attacker could exploit this vulnerability by retrieving the contents of specific memory locations of an affected device. A successful exploit could result in the disclosure of keying materials that are part of the device configuration, which can be used to recover critical system information.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.4 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
ciscoCNA
4.4 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%
VendorProductVersion
ciscoios
12.2\(6\)i1
ciscoios
15.1\(2\)sg8a
ciscoios
15.1\(3\)svg3d
ciscoios
15.1\(3\)svi1b
ciscoios
15.1\(3\)svm3
ciscoios
15.1\(3\)svn2
ciscoios
15.1\(3\)svo1
ciscoios
15.1\(3\)svo2
ciscoios
15.1\(3\)svp1
ciscoios
15.1\(4\)m12c
ciscoios
15.2\(3\)ea1
ciscoios
15.2\(4\)jn1
ciscoios
15.2\(4a\)ea5
ciscoios
15.3\(3\)ja1n
ciscoios
15.3\(3\)jf35
ciscoios
15.3\(3\)ji2
ciscoios
15.3\(3\)jn1
ciscoios
15.3\(3\)jn2
ciscoios
15.6\(2\)sp3b
ciscoios
15.6\(3\)m1
ciscoios
15.6\(3\)m1a
ciscoios
15.6\(3\)m1b
ciscoios
15.6\(3\)m2
ciscoios
15.6\(3\)m2a
ciscoios
15.6\(3\)m3
ciscoios
15.6\(3\)m3a
ciscoios
15.6\(3\)m4
ciscoios
15.6\(3.1\)m
ciscoios
15.7\(3\)m
ciscoios
15.7\(3\)m0a
ciscoios
15.7\(3\)m1
ciscoios_xe
16.6.1
ciscoios_xe
16.6.2
ciscoios_xe
16.6.3
ciscoios_xe
16.6.4
ciscoios_xe
16.6.4a:a
ciscoios_xe
16.6.4s:s
ciscoios_xe
16.7.1
ciscoios_xe
16.7.1a:a
ciscoios_xe
16.7.1b:b
ciscoios_xe
16.7.2
ciscoios_xe
16.7.3
ciscoios_xe
16.7.4
ciscoios_xe
16.8.1
ciscoios_xe
16.8.1a:a
ciscoios_xe
16.8.1b:b
ciscoios_xe
16.8.1c:c
ciscoios_xe
16.8.1d:d
ciscoios_xe
16.8.1e:e
ciscoios_xe
16.8.1s:s
ciscoios_xe
16.8.2
ciscoios_xe
16.9.1
ciscoios_xe
16.9.1a:a
ciscoios_xe
16.9.1b:b
ciscoios_xe
16.9.1c:c
ciscoios_xe
16.9.1d:d
ciscoios_xe
16.9.1s:s
ciscoios_xe
16.9.2
ciscoios_xe
16.9.2a:a
𝑥
= Vulnerable software versions