cbcvebase.
CVE-2019-1867
published 2019-05-10

CVE-2019-1867: A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication on the REST…

PriorityP182critical10CVSS 3.0
AVNACLPRNUINSCCHIHAH
EPSS
30.34%
98.0th percentile
A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication on the REST API. The vulnerability is due to improper validation of API requests. An attacker could exploit this vulnerability by sending a crafted request to the REST API. A successful exploit could allow the attacker to execute arbitrary actions through the REST API with administrative privileges on an affected system.

Affected

6 ranges
VendorProductVersion rangeFixed in
ciscocisco_elastic_services_controller>= unspecified < 4.1.0.1004.1.0.100
ciscocisco_elastic_services_controller>= unspecified < 4.2.0.744.2.0.74
ciscocisco_elastic_services_controller>= unspecified < 4.3.0.1214.3.0.121
ciscocisco_elastic_services_controller>= unspecified < 4.4.0.804.4.0.80
ciscoelastic_services_controller>= 4.1 < 4.54.5
ciscoelastic_services_controller_rest

Detection & IOCsextracted from sources · hover to see the quote

  • Detect unauthenticated REST API requests to Cisco ESC that bypass authentication — monitor for API calls reaching administrative endpoints without valid credentials/session tokens
  • Alert on any unauthenticated remote access attempts to the Cisco Elastic Services Controller (ESC) REST API, particularly requests that result in administrative-level actions
  • ·The vulnerability stems from improper validation of API requests (CWE-287); detection logic should focus on API request structure anomalies that circumvent authentication checks rather than relying solely on credential-based alerting
  • ·No workarounds are available; patching is the only mitigation — ensure detection coverage remains active until software updates are applied

CVSS provenance

nvdv3.010.0CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.