CVE Feed

    Dashboard / CVE / CVE-2019-1842

    CVE-2019-1842

    A vulnerability in the Secure Shell (SSH) authentication function of Cisco IOS XR Software could allow an authenticated, remote attacker to successfully log in to an affected device using two distinct usernames. The vulnerability is due to a logic error that may occur when certain sequences of actions are processed during an SSH login event on the affected device. An attacker could exploit this vulnerability by initiating an SSH session to the device with a specific sequence that presents the two usernames. A successful exploit could result in logging data misrepresentation, user enumeration, or, in certain circumstances, a command authorization bypass. See the Details section for more information.

    Published:Jun 5, 2019
    Last Modified:Nov 21, 2024
    EPS:Jun 5, 2019
    EPSS Score:0.00267
    CVSS Score:5.4

    Affected Products

    Vendor
    Cisco
    Product
    Asr 9001
    Vendor
    Cisco
    Product
    Asr 9006
    Vendor
    Cisco
    Product
    Asr 9010
    Vendor
    Cisco
    Product
    Asr 9901
    Vendor
    Cisco
    Product
    Asr 9904
    Vendor
    Cisco
    Product
    Asr 9906
    Vendor
    Cisco
    Product
    Asr 9910
    Vendor
    Cisco
    Product
    Asr 9912
    Vendor
    Cisco
    Product
    Asr 9922
    Vendor
    Cisco
    Product
    Crs-1 16-slot Line Card Chassis
    Vendor
    Cisco
    Product
    Crs-1 16-slot Single-shelf System
    Vendor
    Cisco
    Product
    Crs-1 4-slot Single-shelf System
    Vendor
    Cisco
    Product
    Crs-1 8-slot Line Card Chassis
    Vendor
    Cisco
    Product
    Crs-1 8-slot Single-shelf System
    Vendor
    Cisco
    Product
    Crs-1 Fabric Card Chassis
    Vendor
    Cisco
    Product
    Crs-1 Line Card Chassis \(dual\)
    Vendor
    Cisco
    Product
    Crs-1 Line Card Chassis \(multi\)
    Vendor
    Cisco
    Product
    Crs-1 Multishelf System
    Vendor
    Cisco
    Product
    Crs-3 16-slot Single-shelf System
    Vendor
    Cisco
    Product
    Crs-3 4-slot Single-shelf System
    Vendor
    Cisco
    Product
    Crs-3 8-slot Single-shelf System
    Vendor
    Cisco
    Product
    Crs-3 Multishelf System
    Vendor
    Cisco
    Product
    Crs-8\/s-b Crs
    Vendor
    Cisco
    Product
    Crs-8\/scrs
    Vendor
    Cisco
    Product
    Crs-x 16-slot Single-shelf System
    Vendor
    Cisco
    Product
    Crs-x Multishelf System
    Vendor
    Cisco
    Product
    Ios Xr Firmware
    Vendor
    Cisco
    Product
    Ncs 6008-8-slot Chassis
    Vendor
    Cisco
    Product
    Network Convergence System 5508

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High