CVE-2019-12656: Cisco Cgr 1000 Firmware

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

A vulnerability in the IOx application environment of multiple Cisco platforms could allow an unauthenticated, remote attacker to cause the IOx web server to stop processing HTTPS requests, resulting in a denial of service (DoS) condition. The vulnerability is due to a Transport Layer Security (TLS) implementation issue. An attacker could exploit this vulnerability by sending crafted TLS packets to the IOx web server on an affected device. A successful exploit could allow the attacker to cause the IOx web server to stop processing HTTPS requests, resulting in a DoS condition.

Affected products

  • Cisco Cgr 1000 Firmware: affected versions not specified
  • Cisco IC3000 Firmware: affected versions not specified
  • Cisco Ie 4000 Firmware: affected versions not specified
  • Cisco Industrial Ethernet 2000 Series Firmware: version 15.2(6)e only
  • Cisco IOS: version 1.6.0.0 only; version 1.8.0 only
  • Cisco IR510 Wpan Firmware: affected versions not specified

Published 2019-09-25. Last modified 2026-06-17.