CVE-2019-1717
Published on: 05/15/2019 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:27:47 PM UTC
Certain versions of Video Surveillance Manager from Cisco contain the following vulnerability:
A vulnerability in the web-based management interface of Cisco Video Surveillance Manager could allow an unauthenticated, remote attacker to access sensitive information. The vulnerability is due to improper validation of parameters handled by the web-based management interface. An attacker could exploit this vulnerability by sending malicious requests to an affected component. A successful exploit could allow the attacker to download arbitrary files from the affected device, which could contain sensitive information.
- CVE-2019-1717 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.
- Affected Vendor/Software:
Cisco - Cisco Video Surveillance Manager version 7.12.1
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | NONE |
CVSS2 Score: 5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Cisco Video Surveillance Manager CVE-2019-1717 Information Disclosure Vulnerability | Third Party Advisory VDB Entry cve.report (archive) text/html |
![]() |
Cisco Video Surveillance Manager Web-Based Management Interface Information Disclosure Vulnerability | Vendor Advisory tools.cisco.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Cisco | Video Surveillance Manager | 7.21 | All | All | All |
Application | Cisco | Video Surveillance Manager | 7.21 | All | All | All |
- cpe:2.3:a:cisco:video_surveillance_manager:7.21:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:video_surveillance_manager:7.21:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE