CVE-2019-1976
published 2019-09-05CVE-2019-1976: A vulnerability in the “plug-and-play” services component of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to access…
PriorityP266critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.98%
78.1th percentile
A vulnerability in the “plug-and-play” services component of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to improper access restrictions on the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to access running configuration information about devices managed by the IND, including administrative credentials.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_industrial_network_director | >= unspecified < 1.6.0 | 1.6.0 |
| cisco | industrial_network_director | < 1.6.0 | 1.6.0 |
| cisco | industrial_network_director_configuration_data | — | — |
| cisco | network_level_service | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect unauthenticated crafted HTTP requests targeting the plug-and-play services component of Cisco IND's web-based management interface, which may indicate exploitation of improper access restrictions to retrieve running configuration data including credentials. ↗
- ·The vulnerability is specifically in the 'plug-and-play' services component of Cisco IND. Exploitation requires no authentication, meaning any unauthenticated HTTP request to this component should be treated as suspicious and monitored. ↗
- ·There are no workarounds available for this vulnerability; patching via Cisco's released software updates is the only remediation path. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xjjh-6mhx-q6jr: A vulnerability in the “plug-and-play” services component of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker t
ghsa_unreviewed·2022-05-24
CVE-2019-1976 [CRITICAL] GHSA-xjjh-6mhx-q6jr: A vulnerability in the “plug-and-play” services component of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker t
A vulnerability in the “plug-and-play” services component of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to improper access restrictions on the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to access running configuration information about devices managed by the IND, including administrative credentials.
Cisco
Cisco Industrial Network Director Configuration Data Information Disclosure Vulnerability
vendor_cisco·2019-09-04·CVSS 7.5
CVE-2019-1976 [HIGH] CWE-200 Cisco Industrial Network Director Configuration Data Information Disclosure Vulnerability
Cisco Industrial Network Director Configuration Data Information Disclosure Vulnerability
A vulnerability in the “plug-and-play” services component of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to access sensitive information on an affected device.
The vulnerability is due to improper access restrictions on the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to access running configuration information about devices managed by the IND, including administrative credentials.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is a
Cisco
Cisco Industrial Network Director Configuration Data Information Disclosure Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1976 Cisco Industrial Network Director Configuration Data Information Disclosure Vulnerability
CVE-2019-1976: Cisco Industrial Network Director Configuration Data Information Disclosure Vulnerability
A vulnerability in the “plug-and-play” services component of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to improper access restrictions on the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to access running configuration information about devices managed by the IND, including administrative credentials. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-200, CWE-200
Bug IDs: CSCvn446
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-09-05
Published