CVE-2019-1895

Severity
9.8CRITICAL
EPSS
2.4%
top 15.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 7
Latest updateMay 24

Description

A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session of an administrative user on an affected device. The vulnerability is due to an insufficient authentication mechanism used to establish a VNC session. An attacker could exploit this vulnerability by intercepting an administrator VNC session request prior to login. A successful exploi

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

🔴Vulnerability Details

2
GHSA
GHSA-4wqg-2gvp-c2c4: A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an u2022-05-24
CVEList
Cisco Enterprise NFV Infrastructure Software VNC Authentication Bypass Vulnerability2019-08-07

📋Vendor Advisories

1
Cisco
Cisco Enterprise NFV Infrastructure Software VNC Authentication Bypass Vulnerability2019-08-07
CVE-2019-1895 (CRITICAL CVSS 9.8) | A vulnerability in the Virtual Netw | cvebase.io