#VU20388 Cross-site request forgery in Cisco IOS XE - CVE-2019-12624
Published: August 26, 2019
Cisco IOS XE
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to perform cross-site request forgery attacks.
The vulnerability exists due to insufficient validation of the HTTP request origin in the web-based management interface. A remote attacker can trick the victim to visit a specially crafted web page and follow a crafted link.
This vulnerability affects the following Cisco products that are running any of the 3.xE releases of Cisco IOS XE Software:
- 5760 Wireless LAN Controllers
- Catalyst 3650 Series Switches
- Catalyst 3850 Series Switches
- Catalyst 4500E Supervisor Engine 8-E (Wireless) Switches