CVE-2019-1854
published 2019-05-03CVE-2019-1854: A vulnerability in the management web interface of Cisco Expressway Series could allow an authenticated, remote attacker to perform a directory traversal…
PriorityP428medium4.3CVSS 3.0
AVNACLPRLUINSUCLINAN
EPSS
3.82%
88.8th percentile
A vulnerability in the management web interface of Cisco Expressway Series could allow an authenticated, remote attacker to perform a directory traversal attack against an affected device. The vulnerability is due to insufficient input validation on the web interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web interface. A successful exploit could allow the attacker to bypass security restrictions and access the web interface of a Cisco Unified Communications Manager associated with the affected device. Valid credentials would still be required to access the Cisco Unified Communications Manager interface.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_expressway | >= unspecified < X12.5.2 | X12.5.2 |
| cisco | expressway_series_directory | — | — |
| cisco | telepresence_video_communication_server | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_cisco4.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r7gg-wq5p-qhgv: A vulnerability in the management web interface of Cisco Expressway Series could allow an authenticated, remote attacker to perform a directory traver
ghsa_unreviewed·2022-05-24
CVE-2019-1854 [MEDIUM] GHSA-r7gg-wq5p-qhgv: A vulnerability in the management web interface of Cisco Expressway Series could allow an authenticated, remote attacker to perform a directory traver
A vulnerability in the management web interface of Cisco Expressway Series could allow an authenticated, remote attacker to perform a directory traversal attack against an affected device. The vulnerability is due to insufficient input validation on the web interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web interface. A successful exploit could allow the attacker to bypass security restrictions and access the web interface of a Cisco Unified Communications Manager associated with the affected device. Valid credentials would still be required to access the Cisco Unified Communications Manager interface.
Cisco
Cisco Expressway Series Directory Traversal Vulnerability
vendor_cisco·2019-05-01·CVSS 4.1
CVE-2019-1854 [MEDIUM] CWE-22 Cisco Expressway Series Directory Traversal Vulnerability
Cisco Expressway Series Directory Traversal Vulnerability
A vulnerability in the management web interface of Cisco Expressway Series could allow an authenticated, remote attacker to perform a directory traversal attack against an affected device.
The vulnerability is due to insufficient input validation on the web interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web interface. A successful exploit could allow the attacker to bypass security restrictions and access the web interface of a Cisco Unified Communications Manager associated with the affected device. Valid credentials would still be required to access the Cisco Unified Communications Manager interface.
There are no workarounds that address this vulnerability.
This advisory is avail
Cisco
Cisco Expressway Series Directory Traversal Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1854 Cisco Expressway Series Directory Traversal Vulnerability
CVE-2019-1854: Cisco Expressway Series Directory Traversal Vulnerability
A vulnerability in the management web interface of Cisco Expressway Series could allow an authenticated, remote attacker to perform a directory traversal attack against an affected device. The vulnerability is due to insufficient input validation on the web interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web interface. A successful exploit could allow the attacker to bypass security restrictions and access the web interface of a Cisco Unified Communications Manager associated with the affected device. Valid credentials would still be required to access the Cisco Unified Communications Manager interface. There are no
CVSS: 3.0
CWE: CWE-22, CWE-22
Bug IDs: CSCvo47769
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/152963/Cisco-Expressway-Gateway-11.5.1-Directory-Traversal.htmlhttp://seclists.org/fulldisclosure/2019/May/28http://www.securityfocus.com/bid/108154https://seclists.org/bugtraq/2019/May/49https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-expressway-traversalhttp://packetstormsecurity.com/files/152963/Cisco-Expressway-Gateway-11.5.1-Directory-Traversal.htmlhttp://seclists.org/fulldisclosure/2019/May/28http://www.securityfocus.com/bid/108154https://seclists.org/bugtraq/2019/May/49https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-expressway-traversal
2019-05-03
Published