CVE-2019-1841
Summary
| CVE | CVE-2019-1841 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-18 02:29:00 UTC |
| Updated | 2019-10-09 23:48:00 UTC |
| Description | A vulnerability in the Software Image Management feature of Cisco DNA Center could allow an authenticated, remote attacker to access to internal services without additional authentication. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending arbitrary HTTP requests to internal services. An exploit could allow the attacker to bypass any firewall or other protections to access unauthorized internal services. DNAC versions prior to 1.2.5 are affected. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Dna Center | All | All | All | All |
| Application | Cisco | Dna Center | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco DNA Center Unintended Proxy Via SWIM Import Interface Vulnerability | CISCO | tools.cisco.com | Vendor Advisory |
| Cisco DNA Center Software CVE-2019-1841 Access Bypass Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.