CVE-2019-1867
published 2019-05-10CVE-2019-1867: A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication on the REST…
PriorityP182critical10CVSS 3.0
AVNACLPRNUINSCCHIHAH
EPSS
30.34%
98.0th percentile
A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication on the REST API. The vulnerability is due to improper validation of API requests. An attacker could exploit this vulnerability by sending a crafted request to the REST API. A successful exploit could allow the attacker to execute arbitrary actions through the REST API with administrative privileges on an affected system.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_elastic_services_controller | >= unspecified < 4.1.0.100 | 4.1.0.100 |
| cisco | cisco_elastic_services_controller | >= unspecified < 4.2.0.74 | 4.2.0.74 |
| cisco | cisco_elastic_services_controller | >= unspecified < 4.3.0.121 | 4.3.0.121 |
| cisco | cisco_elastic_services_controller | >= unspecified < 4.4.0.80 | 4.4.0.80 |
| cisco | elastic_services_controller | >= 4.1 < 4.5 | 4.5 |
| cisco | elastic_services_controller_rest | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect unauthenticated REST API requests to Cisco ESC that bypass authentication — monitor for API calls reaching administrative endpoints without valid credentials/session tokens ↗
- →Alert on any unauthenticated remote access attempts to the Cisco Elastic Services Controller (ESC) REST API, particularly requests that result in administrative-level actions ↗
- ·The vulnerability stems from improper validation of API requests (CWE-287); detection logic should focus on API request structure anomalies that circumvent authentication checks rather than relying solely on credential-based alerting ↗
- ·No workarounds are available; patching is the only mitigation — ensure detection coverage remains active until software updates are applied ↗
CVSS provenance
nvdv3.010.0CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gfx3-865x-23hf: A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication on
ghsa_unreviewed·2022-05-24
CVE-2019-1867 [CRITICAL] GHSA-gfx3-865x-23hf: A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication on
A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication on the REST API. The vulnerability is due to improper validation of API requests. An attacker could exploit this vulnerability by sending a crafted request to the REST API. A successful exploit could allow the attacker to execute arbitrary actions through the REST API with administrative privileges on an affected system.
Cisco
Cisco Elastic Services Controller REST API Authentication Bypass Vulnerability
vendor_cisco·2019-05-07·CVSS 10.0
CVE-2019-1867 [CRITICAL] CWE-287 Cisco Elastic Services Controller REST API Authentication Bypass Vulnerability
Cisco Elastic Services Controller REST API Authentication Bypass Vulnerability
A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication on the REST API.
The vulnerability is due to improper validation of API requests. An attacker could exploit this vulnerability by sending a crafted request to the REST API. A successful exploit could allow the attacker to execute arbitrary actions through the REST API with administrative privileges on an affected system.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdv
Cisco
Cisco Elastic Services Controller REST API Authentication Bypass Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1867 Cisco Elastic Services Controller REST API Authentication Bypass Vulnerability
CVE-2019-1867: Cisco Elastic Services Controller REST API Authentication Bypass Vulnerability
A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication on the REST API. The vulnerability is due to improper validation of API requests. An attacker could exploit this vulnerability by sending a crafted request to the REST API. A successful exploit could allow the attacker to execute arbitrary actions through the REST API with administrative privileges on an affected system. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-287, CWE-287
Bug IDs: CSCvn82921
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-05-10
Published