HIGH · 7.5

CVE-2019-12658

A vulnerability in the filesystem resource management code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to exhaust filesystem resources on an affected device and cause a de...

Vulnerability Description

A vulnerability in the filesystem resource management code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to exhaust filesystem resources on an affected device and cause a denial of service (DoS) condition. The vulnerability is due to ineffective management of the underlying filesystem resources. An attacker could exploit this vulnerability by performing specific actions that result in messages being sent to specific operating system log files. A successful exploit could allow the attacker to exhaust available filesystem space on an affected device. This could cause the device to crash and reload, resulting in a DoS condition for clients whose network traffic is transiting the device. Upon reload of the device, the impacted filesystem space is cleared, and the device will return to normal operation. However, continued exploitation of this vulnerability could cause subsequent forced crashes and reloads, which could lead to an extended DoS condition.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
CiscoIos Xe16.6.1
Cisco1100 Integrated Services R-
Cisco4221 Integrated Services R-
Cisco4321 Integrated Services R-
Cisco4331 Integrated Services R-
Cisco4351 Integrated Services R-
Cisco4431 Integrated Services R-
Cisco4451-X Integrated Services R-
CiscoAsr 1000-
CiscoAsr 1001-Hx R-
CiscoAsr 1001-X R-
CiscoAsr 1002-Hx R-
CiscoAsr 1002-X R-
CiscoAsr 900-
CiscoAsr 900 -
CiscoAsr 920-10Sz-Pd R-
CiscoAsr 920-12Cz-A R-
CiscoAsr 920-12Cz-D R-
CiscoAsr 920-12Sz-Im R-
CiscoAsr 920-24Sz-Im R-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-12658?

CVE-2019-12658 is a vulnerability with a CVSS score of 7.5 (HIGH). A vulnerability in the filesystem resource management code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to exhaust filesystem resources on an affected device and cause a de...

How severe is CVE-2019-12658?

CVE-2019-12658 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-12658?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios Xe, Cisco 1100 Integrated Services R, Cisco 4221 Integrated Services R, Cisco 4321 Integrated Services R, Cisco 4331 Integrated Services R.