Description
A vulnerability in the web-based management interface of Cisco HyperFlex HX-Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected system by using a web browser and with the privileges of the user.
Published: 2019-05-03
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-10414 A vulnerability in the web-based management interface of Cisco HyperFlex HX-Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected system by using a web browser and with the privileges of the user.
History

Thu, 21 Nov 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Cisco Hx220c Af M5 Hx220c Af M5 Firmware Hx220c All Nvme M5 Hx220c All Nvme M5 Firmware Hx220c Edge M5 Hx220c Edge M5 Firmware Hx220c M5 Hx220c M5 Firmware Hx240c Af M5 Hx240c Af M5 Firmware Hx240c Large Form Factor Hx240c Large Form Factor Firmware Hx240c M5 Hx240c M5 Firmware Ucs B200 M5 Ucs B200 M5 Firmware Ucs B480 M5 Ucs B480 M5 Firmware Ucs C125 M5 Ucs C125 M5 Firmware Ucs C220 M5 Ucs C220 M5 Firmware Ucs C240 M5 Ucs C240 M5 Firmware Ucs C480 M5 Ucs C480 M5 Firmware Ucs C480 Ml Ucs C480 Ml Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2024-11-21T19:32:04.174Z

Reserved: 2018-12-06T00:00:00.000Z

Link: CVE-2019-1857

cve-icon Vulnrichment

Updated: 2024-08-04T18:28:42.871Z

cve-icon NVD

Status : Modified

Published: 2019-05-03T17:29:01.437

Modified: 2024-11-21T04:37:32.597

Link: CVE-2019-1857

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses