CVE-2019-1757: Cisco IOS
Medium severity, CVSS 5.9. EPSS: 1.1% chance of exploitation in the next 30 days.
A vulnerability in the Cisco Smart Call Home feature of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data using an invalid certificate. The vulnerability is due to insufficient certificate validation by the affected software. An attacker could exploit this vulnerability by supplying a crafted certificate to an affected device. A successful exploit could allow the attacker to conduct man-in-the-middle attacks to decrypt confidential information on user connections to the affected software.
Affected products
- Cisco IOS: version 2.3 only; version 12.2(6)i1 only; version 12.4(25e)jap1m only; version 12.4(25e)jap2 only; version 12.4(25e)jap26 only; version 12.4(25e)jaz1 only; …
- Cisco IOS XE: version 3.6.4e only; version 3.6.5ae only; version 3.6.5be only; version 3.6.5e only; version 3.6.6e only; version 3.6.7ae only; …
Published 2019-03-28. Last modified 2026-06-17.