Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-1876

Опубликовано: 20 июн. 2019
Источник: nvd
CVSS3: 4
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

A vulnerability in the HTTPS proxy feature of Cisco Wide Area Application Services (WAAS) Software could allow an unauthenticated, remote attacker to use the Central Manager as an HTTPS proxy. The vulnerability is due to insufficient authentication of proxy connection requests. An attacker could exploit this vulnerability by sending a malicious HTTPS CONNECT message to the Central Manager. A successful exploit could allow the attacker to access public internet resources that would normally be blocked by corporate policies.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:wide_area_application_services:5.5\(7\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:wide_area_application_services:6.1\(1\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:wide_area_application_services:6.4\(3b\):*:*:*:*:*:*:*

EPSS

Процентиль: 83%
0.01967
Низкий

4 Medium

CVSS3

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-306
CWE-306

Связанные уязвимости

CVSS3: 5.3
github
больше 3 лет назад

A vulnerability in the HTTPS proxy feature of Cisco Wide Area Application Services (WAAS) Software could allow an unauthenticated, remote attacker to use the Central Manager as an HTTPS proxy. The vulnerability is due to insufficient authentication of proxy connection requests. An attacker could exploit this vulnerability by sending a malicious HTTPS CONNECT message to the Central Manager. A successful exploit could allow the attacker to access public internet resources that would normally be blocked by corporate policies.

CVSS3: 4
fstec
больше 6 лет назад

Уязвимость прокси-сервера программного пакета Cisco Wide Area Application Services Software, связанная с ошибками аутентификации запросов на подключение к прокси-серверу HTTPS, позволяющая нарушителю использовать WAAS Central Manager в качестве прокси-сервера HTTPS

EPSS

Процентиль: 83%
0.01967
Низкий

4 Medium

CVSS3

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-306
CWE-306