cbcvebase.
CVE-2019-1976
published 2019-09-05

CVE-2019-1976: A vulnerability in the “plug-and-play” services component of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to access…

PriorityP266critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.98%
78.1th percentile
A vulnerability in the “plug-and-play” services component of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to improper access restrictions on the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to access running configuration information about devices managed by the IND, including administrative credentials.

Affected

4 ranges
VendorProductVersion rangeFixed in
ciscocisco_industrial_network_director>= unspecified < 1.6.01.6.0
ciscoindustrial_network_director< 1.6.01.6.0
ciscoindustrial_network_director_configuration_data
cisconetwork_level_service

Detection & IOCsextracted from sources · hover to see the quote

  • Detect unauthenticated crafted HTTP requests targeting the plug-and-play services component of Cisco IND's web-based management interface, which may indicate exploitation of improper access restrictions to retrieve running configuration data including credentials.
  • ·The vulnerability is specifically in the 'plug-and-play' services component of Cisco IND. Exploitation requires no authentication, meaning any unauthenticated HTTP request to this component should be treated as suspicious and monitored.
  • ·There are no workarounds available for this vulnerability; patching via Cisco's released software updates is the only remediation path.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.