CVE-2019-1975

Severity
6.1MEDIUM
EPSS
0.5%
top 35.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 18
Latest updateMay 24

Description

A vulnerability in the web-based interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to execute a cross-frame scripting (XFS) attack on an affected device. This vulnerability is due to insufficient HTML iframe protection. An attacker could exploit this vulnerability by directing a user to an attacker-controlled web page that contains a malicious HTML iframe. A successful exploit could allow the attacker to conduct clickjacking or other clientside browser attacks

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages6 packages

🔴Vulnerability Details

2
GHSA
GHSA-hxvj-9m68-2v8w: A vulnerability in the web-based interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to execute a cross-frame script2022-05-24
CVEList
Cisco HyperFlex Software Cross-Frame Scripting Vulnerability2019-09-18

📋Vendor Advisories

1
Cisco
Cisco HyperFlex Software Cross-Frame Scripting Vulnerability2019-09-18

💬Community

1
Bugzilla
CVE-2019-19241 kernel: privilege escalation via io_uring offload of sendmsg() onto kernel thread with kernel creds2019-12-18
CVE-2019-1975 (MEDIUM CVSS 6.1) | A vulnerability in the web-based in | cvebase.io