Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-1857


A vulnerability in the web-based management interface of Cisco HyperFlex HX-Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected system by using a web browser and with the privileges of the user.


Published

2019-05-03T17:29:01.437

Last Modified

2024-11-21T04:37:32.597

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 6.1 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-352
  • Type: Primary
    CWE-352

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco hx220c_m5_firmware 3.0\(1a\) Yes
Hardware cisco hx220c_m5 - No
Operating System cisco hx240c_m5_firmware 3.0\(1a\) Yes
Hardware cisco hx240c_m5 - No
Operating System cisco hx240c_large_form_factor_firmware 3.0\(1a\) Yes
Hardware cisco hx240c_large_form_factor - No
Operating System cisco hx220c_all_nvme_m5_firmware 3.0\(1a\) Yes
Hardware cisco hx220c_all_nvme_m5 - No
Operating System cisco hx220c_af_m5_firmware 3.0\(1a\) Yes
Hardware cisco hx220c_af_m5 - No
Operating System cisco hx240c_af_m5_firmware 3.0\(1a\) Yes
Hardware cisco hx240c_af_m5 - No
Operating System cisco hx220c_edge_m5_firmware 3.0\(1a\) Yes
Hardware cisco hx220c_edge_m5 - No
Operating System cisco ucs_b200_m5_firmware 3.0\(1a\) Yes
Hardware cisco ucs_b200_m5 - No
Operating System cisco ucs_b480_m5_firmware 3.0\(1a\) Yes
Hardware cisco ucs_b480_m5 - No
Operating System cisco ucs_c480_m5_firmware 3.0\(1a\) Yes
Hardware cisco ucs_c480_m5 - No
Operating System cisco ucs_c125_m5_firmware 3.0\(1a\) Yes
Hardware cisco ucs_c125_m5 - No
Operating System cisco ucs_c220_m5_firmware 3.0\(1a\) Yes
Hardware cisco ucs_c220_m5 - No
Operating System cisco ucs_c240_m5_firmware 3.0\(1a\) Yes
Hardware cisco ucs_c240_m5 - No
Operating System cisco ucs_c480_ml_firmware 3.0\(1a\) Yes
Hardware cisco ucs_c480_ml - No

References