Vulnslist

find the latest Cisco vulnerabilities

Cisco HyperFlex Unauthenticated Statistics Retrieval Vulnerability

cisco-sa-20190220-hyper-retrieve · Medium · Published · Updated

A vulnerability in the Graphite service of Cisco HyperFlex software could allow an unauthenticated, remote attacker to retrieve data from the Graphite service. The vulnerability is due to insufficient authentication controls. An attacker could exploit this vulnerability by sending crafted requests to the Graphite service. A successful exploit could allow the attacker to retrieve any statistics from the Graphite service. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190220-hyper-retrieve

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2019-1666
Cisco Bug IDsCSCvj95580
CVSS ScoreBase 5.3
Base 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco HyperFlex HX-Series

Related Products

Product CVE Evidence
Cisco HyperFlex HX-Series CVE-2019-1666 Cisco OpenVuln