// For flags

CVE-2019-1717

Cisco Video Surveillance Manager Web-Based Management Interface Information Disclosure Vulnerability

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

A vulnerability in the web-based management interface of Cisco Video Surveillance Manager could allow an unauthenticated, remote attacker to access sensitive information. The vulnerability is due to improper validation of parameters handled by the web-based management interface. An attacker could exploit this vulnerability by sending malicious requests to an affected component. A successful exploit could allow the attacker to download arbitrary files from the affected device, which could contain sensitive information.

Una vulnerabilidad en la interfaz de administración basada en web de Cisco Video Surveillance Manager podría permitir que un atacante remoto no identificado acceda a información confidencial. La vulnerabilidad se debe a la comprobación incorrecta de los parámetros manejados por la interfaz de administración basada en web. Un atacante podría explotar esta vulnerabilidad enviando solicitudes maliciosas a un componente afectado. Una explotación con éxito podría permitir al atacante descargar archivos arbitrarios del dispositivo afectado, que podría contener información confidencial.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
None
Automatable
Yes
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2018-12-06 CVE Reserved
  • 2019-05-15 CVE Published
  • 2024-10-05 EPSS Updated
  • 2024-11-19 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cisco
Search vendor "Cisco"
Video Surveillance Manager
Search vendor "Cisco" for product "Video Surveillance Manager"
7.21
Search vendor "Cisco" for product "Video Surveillance Manager" and version "7.21"
-
Affected