CVE-2019-1895
published 2019-08-07CVE-2019-1895: A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an…
PriorityP268critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.28%
81.4th percentile
A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session of an administrative user on an affected device. The vulnerability is due to an insufficient authentication mechanism used to establish a VNC session. An attacker could exploit this vulnerability by intercepting an administrator VNC session request prior to login. A successful exploit could allow the attacker to watch the administrator console session or interact with it, allowing admin access to the affected device.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_enterprise_nfv_infrastructure_software | >= unspecified < 3.12.1 | 3.12.1 |
| cisco | enterprise_network_function_virtualization_infrastructure | < 3.12.1 | 3.12.1 |
| cisco | enterprise_nfv_infrastructure | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit vector targets VNC console session establishment on Cisco NFVIS — monitor for unauthenticated VNC session requests (typically TCP port 5900/5901) directed at NFVIS management interfaces, especially those that precede or bypass the login prompt. ↗
- →The vulnerability is classified under CWE-306 (Missing Authentication for Critical Function) — alert on VNC sessions to NFVIS that complete without a corresponding authentication exchange. ↗
- →Track Cisco bug IDs CSCvm75496 and CSCvp00281 for patch status; unpatched NFVIS devices are targets — inventory and flag devices running affected NFVIS versions. ↗
- ·No workarounds are available for this vulnerability; the only remediation is applying Cisco's software update. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Enterprise NFV Infrastructure Software VNC Authentication Bypass Vulnerability
vendor_cisco·2019-08-07·CVSS 9.8
CVE-2019-1895 [CRITICAL] CWE-306 Cisco Enterprise NFV Infrastructure Software VNC Authentication Bypass Vulnerability
Cisco Enterprise NFV Infrastructure Software VNC Authentication Bypass Vulnerability
A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session of an administrative user on an affected device.
The vulnerability is due to an insufficient authentication mechanism used to establish a VNC session. An attacker could exploit this vulnerability by intercepting an administrator VNC session request prior to login. A successful exploit could allow the attacker to watch the administrator console session or interact with it, allowing admin access to the affected device.
Cisco has released software updates that address this vulnerability. There ar
Cisco
Cisco Enterprise NFV Infrastructure Software VNC Authentication Bypass Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1895 Cisco Enterprise NFV Infrastructure Software VNC Authentication Bypass Vulnerability
CVE-2019-1895: Cisco Enterprise NFV Infrastructure Software VNC Authentication Bypass Vulnerability
A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session of an administrative user on an affected device. The vulnerability is due to an insufficient authentication mechanism used to establish a VNC session. An attacker could exploit this vulnerability by intercepting an administrator VNC session request prior to login. A successful exploit could allow the attacker to watch the administrator console session or interact with it, allowing admin access to the affected device. Cisco has released software updates that address this vulnerabi
GHSA
GHSA-4wqg-2gvp-c2c4: A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an u
ghsa_unreviewed·2022-05-24
CVE-2019-1895 [CRITICAL] CWE-306 GHSA-4wqg-2gvp-c2c4: A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an u
A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session of an administrative user on an affected device. The vulnerability is due to an insufficient authentication mechanism used to establish a VNC session. An attacker could exploit this vulnerability by intercepting an administrator VNC session request prior to login. A successful exploit could allow the attacker to watch the administrator console session or interact with it, allowing admin access to the affected device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-08-07
Published