CVE-2019-1869: Cisco Staros

High severity, CVSS 7.5. EPSS: 2.6% chance of exploitation in the next 30 days.

A vulnerability in the internal packet-processing functionality of the Cisco StarOS operating system running on virtual platforms could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting in a denial of service (DoS) condition. The vulnerability is due to a logic error that may occur under specific traffic conditions. An attacker could exploit this vulnerability by sending a series of crafted packets to an affected device. A successful exploit could allow the attacker to prevent the targeted service interface from receiving any traffic, which would lead to a DoS condition on the affected interface. The device may have to be manually reloaded to recover from exploitation of this vulnerability.

Affected products

  • Cisco Staros: from 21.6, before 21.6.13 (fixed in 21.6.13); from 21.6b, before 21.6b.16 (fixed in 21.6b.16); from 21.7, before 21.7.11 (fixed in 21.7.11); from 21.8, before 21.8.10 (fixed in 21.8.10); from 21.9, before 21.9.7 (fixed in 21.9.7); from 21.10, before 21.10.2 (fixed in 21.10.2); …

Published 2019-06-20. Last modified 2026-06-17.