CVE-2019-12669: Cisco IOS

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

A vulnerability in the RADIUS Change of Authorization (CoA) code of Cisco TrustSec, a feature within Cisco IOS XE Software, could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of a malformed packet. An attacker could exploit this vulnerability by sending a malformed packet to an affected device. A successful exploit could allow the attacker to cause a DoS condition on the affected device.

Affected products

  • Cisco IOS: version 15.2(3)e only; version 15.2(3)e5 only; version 16.11.1 only

Published 2019-09-25. Last modified 2026-06-17.