RULE(RULE ID:324057)

Rule General Information
Release Date: 2020-01-17
Rule Name: Cisco IOS XE WebUI Authenticated Command Injection Vulnerability (CVE-2019-12651)
Severity:
CVE ID:
Rule Protection Details
Description: Cisco ios xe webui authenticated command injection vulnerability (cve-2019-12651).
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Others
Reference: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190925-awr
https://nvd.nist.gov/vuln/detail/CVE-2019-12651
https://www.auscert.org.au/bulletins/ESB-2019.3615.2/
https://www.auscert.org.au/bulletins/ESB-2019.3615/
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190925-webui-cmd-injection