Cisco HyperFlex HX-Series Web-Based Management Interface Cross-Site Request Forgery Vulnerability
Published May 3, 2019
8.8
HIGHCVSS 3.0
EPSS 0.59%
Description
A vulnerability in the web-based management interface of Cisco HyperFlex HX-Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected system by using a web browser and with the privileges of the user.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<4.0(1a)
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Cisco | Cisco HyperFlex HX-Series | n/a |
|
Configuration 1
- 3.0\(1a\)
Configuration 2
- 3.0\(1a\)
Configuration 3
- 3.0\(1a\)
Running on/with
- n/a
Configuration 4
- 3.0\(1a\)
Running on/with
- n/a
Configuration 5
- 3.0\(1a\)
Running on/with
- n/a
Configuration 6
- 3.0\(1a\)
Running on/with
- n/a
Configuration 7
- 3.0\(1a\)
Running on/with
- n/a
Configuration 8
- 3.0\(1a\)
Running on/with
- n/a
Configuration 9
- 3.0\(1a\)
Running on/with
- n/a
Configuration 10
- 3.0\(1a\)
Running on/with
- n/a
Configuration 11
- 3.0\(1a\)
Running on/with
- n/a
Configuration 12
- 3.0\(1a\)
Running on/with
- n/a
Configuration 13
- 3.0\(1a\)
Running on/with
- n/a
Configuration 14
- 3.0\(1a\)
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- http://www.securityfocus.com/bid/108163 vdb-entryx_refsource_BID
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-hyperflex-csrf vendor-advisoryx_refsource_CISCOVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/108163 | vdb-entryx_refsource_BID | |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-hyperflex-csrf | vendor-advisoryx_refsource_CISCOVendor Advisory |
Change history (0)
No recorded changes yet.