Security Advisory

CVE-2019-12659

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-09-25 20:15:33
Last updated 2024-11-19 18:55:47
Assigner cisco
State PUBLISHED

Description

A vulnerability in the HTTP server code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the HTTP server to crash. The vulnerability is due to a logical error in the logging mechanism. An attacker could exploit this vulnerability by generating a high amount of long-lived connections to the HTTP service on the device. A successful exploit could allow the attacker to cause the HTTP server to crash.