Vulnslist

find the latest Cisco vulnerabilities

Cisco Managed Services Accelerator Open Redirect Vulnerability

cisco-sa-20191106-msa-open-redirect · Medium · Published · Updated

A vulnerability in the web interface of Cisco Managed Services Accelerator (MSX) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of the parameters of an HTTP request. An attacker could exploit this vulnerability by intercepting a user's HTTP request and modifying it into a request that causes the web interface to redirect the user to a specific malicious URL. A successful exploit could allow the attacker to redirect a user to a malicious web page. This type of vulnerability is known as an open redirect attack and is used in phishing attacks that get users to unknowingly visit malicious sites. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191106-msa-open-redirect

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2019-15974
Cisco Bug IDsCSCvr02093
CVSS ScoreBase 4.7
Base 4.7 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco Managed Services Accelerator

CSAF Product Statuses

Product Status Source CVE Rows
Cisco Managed Services Accelerator known_affected cisco_csaf CVE-2019-15974 1

Related Products

Product CVE Evidence
Cisco Managed Services Accelerator CVE-2019-15974 Cisco OpenVuln