CVE-2019-1975
Severity
6.1MEDIUM
EPSS
0.5%
top 35.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 18
Latest updateMay 24
Description
A vulnerability in the web-based interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to execute a cross-frame scripting (XFS) attack on an affected device. This vulnerability is due to insufficient HTML iframe protection. An attacker could exploit this vulnerability by directing a user to an attacker-controlled web page that contains a malicious HTML iframe. A successful exploit could allow the attacker to conduct clickjacking or other clientside browser attacks…
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7
Affected Packages6 packages
🔴Vulnerability Details
2📋Vendor Advisories
1💬Community
1Bugzilla▶
CVE-2019-19241 kernel: privilege escalation via io_uring offload of sendmsg() onto kernel thread with kernel creds↗2019-12-18