← back
CVE-2019-1917

Cisco Vision Dynamic Signage Director REST API Authentication Bypass Vulnerability

CVSS 9.1 CRITICALEPSS 5.3%CWE-287
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.1EPSS 5.3%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
17 Jul 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability in the REST API interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to bypass authentication on an affected system. The vulnerability is due to insufficient validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to execute arbitrary actions through the REST API with administrative privileges on the affected system. The REST API is enabled by default and cannot be disabled.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →