Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-1841

Опубликовано: 18 апр. 2019
Источник: nvd
CVSS3: 6.5
CVSS3: 8.1
CVSS2: 5.5
EPSS Низкий

Описание

A vulnerability in the Software Image Management feature of Cisco DNA Center could allow an authenticated, remote attacker to access to internal services without additional authentication. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending arbitrary HTTP requests to internal services. An exploit could allow the attacker to bypass any firewall or other protections to access unauthorized internal services. DNAC versions prior to 1.2.5 are affected.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:catalyst_center:*:*:*:*:*:*:*:*
Версия до 1.2.5 (исключая)

EPSS

Процентиль: 78%
0.01152
Низкий

6.5 Medium

CVSS3

8.1 High

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-441
CWE-20

Связанные уязвимости

CVSS3: 8.1
github
больше 3 лет назад

A vulnerability in the Software Image Management feature of Cisco DNA Center could allow an authenticated, remote attacker to access to internal services without additional authentication. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending arbitrary HTTP requests to internal services. An exploit could allow the attacker to bypass any firewall or other protections to access unauthorized internal services. DNAC versions prior to 1.2.5 are affected.

CVSS3: 6.5
fstec
почти 7 лет назад

Уязвимость компонента Software Image Management службы управления идентификацией системы управления сетью Cisco Digital Network Architecture Center, позволяющая нарушителю получить доступ к внутренним службам

EPSS

Процентиль: 78%
0.01152
Низкий

6.5 Medium

CVSS3

8.1 High

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-441
CWE-20