CVE-2019-12659: Cisco IOS XE
High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.
A vulnerability in the HTTP server code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the HTTP server to crash. The vulnerability is due to a logical error in the logging mechanism. An attacker could exploit this vulnerability by generating a high amount of long-lived connections to the HTTP service on the device. A successful exploit could allow the attacker to cause the HTTP server to crash.
Affected products
- Cisco IOS XE: version 16.10.1 only
Published 2019-09-25. Last modified 2026-06-17.