Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-1903

Опубликовано: 20 июн. 2019
Источник: nvd
CVSS3: 6.5
CVSS3: 9.1
CVSS2: 6.4
EPSS Низкий

Описание

A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of service (DoS) condition. The vulnerability is due to improper restrictions on XML entities. An attacker could exploit this vulnerability by sending malicious requests to a targeted system that contain references within XML entities. An exploit could allow the attacker to retrieve files from the local system, resulting in the disclosure of sensitive information, or cause the application to consume available resources, resulting in a DoS condition.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:security_manager:4.14:sp2:*:*:*:*:*:*

EPSS

Процентиль: 72%
0.00709
Низкий

6.5 Medium

CVSS3

9.1 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-611
CWE-611

Связанные уязвимости

CVSS3: 9.1
github
больше 3 лет назад

A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of service (DoS) condition. The vulnerability is due to improper restrictions on XML entities. An attacker could exploit this vulnerability by sending malicious requests to a targeted system that contain references within XML entities. An exploit could allow the attacker to retrieve files from the local system, resulting in the disclosure of sensitive information, or cause the application to consume available resources, resulting in a DoS condition.

CVSS3: 6.5
fstec
больше 6 лет назад

Уязвимость программного средства для создания отчетов для развернутых средств безопасности Cisco Security Manager, связанная с ошибками ограничения XML-ссылок на внешние объекты, позволяющая нарушителю получить доступ к конфиденциальной информации и вызвать отказ в обслуживании

EPSS

Процентиль: 72%
0.00709
Низкий

6.5 Medium

CVSS3

9.1 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-611
CWE-611