A vulnerability in the web-based management interface of Cisco HyperFlex HX-Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected system by using a web browser and with the privileges of the user.
2019-05-03T17:29:01.437
2024-11-21T04:37:32.597
Modified
CVSSv3.0: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | cisco | hx220c_m5_firmware | 3.0\(1a\) | Yes |
Hardware | cisco | hx220c_m5 | - | No |
Operating System | cisco | hx240c_m5_firmware | 3.0\(1a\) | Yes |
Hardware | cisco | hx240c_m5 | - | No |
Operating System | cisco | hx240c_large_form_factor_firmware | 3.0\(1a\) | Yes |
Hardware | cisco | hx240c_large_form_factor | - | No |
Operating System | cisco | hx220c_all_nvme_m5_firmware | 3.0\(1a\) | Yes |
Hardware | cisco | hx220c_all_nvme_m5 | - | No |
Operating System | cisco | hx220c_af_m5_firmware | 3.0\(1a\) | Yes |
Hardware | cisco | hx220c_af_m5 | - | No |
Operating System | cisco | hx240c_af_m5_firmware | 3.0\(1a\) | Yes |
Hardware | cisco | hx240c_af_m5 | - | No |
Operating System | cisco | hx220c_edge_m5_firmware | 3.0\(1a\) | Yes |
Hardware | cisco | hx220c_edge_m5 | - | No |
Operating System | cisco | ucs_b200_m5_firmware | 3.0\(1a\) | Yes |
Hardware | cisco | ucs_b200_m5 | - | No |
Operating System | cisco | ucs_b480_m5_firmware | 3.0\(1a\) | Yes |
Hardware | cisco | ucs_b480_m5 | - | No |
Operating System | cisco | ucs_c480_m5_firmware | 3.0\(1a\) | Yes |
Hardware | cisco | ucs_c480_m5 | - | No |
Operating System | cisco | ucs_c125_m5_firmware | 3.0\(1a\) | Yes |
Hardware | cisco | ucs_c125_m5 | - | No |
Operating System | cisco | ucs_c220_m5_firmware | 3.0\(1a\) | Yes |
Hardware | cisco | ucs_c220_m5 | - | No |
Operating System | cisco | ucs_c240_m5_firmware | 3.0\(1a\) | Yes |
Hardware | cisco | ucs_c240_m5 | - | No |
Operating System | cisco | ucs_c480_ml_firmware | 3.0\(1a\) | Yes |
Hardware | cisco | ucs_c480_ml | - | No |