CVE-2019-1841
Last modified
CVE-2019-1841 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A vulnerability in the Software Image Management feature of Cisco DNA Center could allow an authenticated, remote attacker to access to internal services without additional authentication. The vulnerability is due to insufficient validation of user-supplied input. EPSS estimates a 2.64% chance of exploitation in the next 30 days.
Description
A vulnerability in the Software Image Management feature of Cisco DNA Center could allow an authenticated, remote attacker to access to internal services without additional authentication. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending arbitrary HTTP requests to internal services. An exploit could allow the attacker to bypass any firewall or other protections to access unauthorized internal services. DNAC versions prior to 1.2.5 are affected.
Metrics
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Catalyst Center | < 1.2.5 |
References
- http://www.securityfocus.com/bid/108084Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/108084Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-1841?
How severe is CVE-2019-1841?
How do I fix CVE-2019-1841?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-18394A Server Side Request Forgery (SSRF) vulnerability in Favico…9.8
- CVE-2019-18396An issue was discovered in certain Oi third-party firmware t…7.2
- CVE-2019-18397A buffer overflow in the fribidi_get_par_embedding_levels_ex…7.8
- CVE-2019-1840A vulnerability in the DHCPv6 input packet processor of Cisc…8.6
- CVE-2019-18408archive_read_format_rar_read_data in archive_read_support_fo…7.5
- CVE-2019-18409The ruby_parser-legacy (aka legacy) gem 1.0.0 for Ruby allow…7.8
- CVE-2019-18411Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CS…8.8
- CVE-2019-18412JetBrains IDETalk plugin before version 193.4099.10 allows X…7.5
- CVE-2019-18413In TypeStack class-validator 0.10.2, validate() input valida…9.8
- CVE-2019-18414Sourcecodester Restaurant Management System 1.0 is affected …8.8
- CVE-2019-18415Sourcecodester Restaurant Management System 1.0 allows XSS v…6.1
- CVE-2019-18416Sourcecodester Restaurant Management System 1.0 allows XSS v…6.1
Are you affected by CVE-2019-1841?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
