CVE-2019-16029: Cisco Smart Software Manager On-Prem Web Interface Denial of Service Vulnerability
A vulnerability in the application programming interface (API) of Cisco Smart Software Manager On-Prem could allow an unauthenticated, remote attacker to change user account information which can prevent users from logging in, resulting in a denial of service (DoS) condition of the web interface. The vulnerability is due to the lack of input validation in the API. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. An exploit could allow the attacker to change or corrupt user account information which could grant the attacker administrator access or prevent legitimate user access to the web interface, resulting in a denial of service (DoS) condition.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-16029?
CVE-2019-16029 is a vulnerability in the API of Cisco Smart Software Manager On-Prem that allows an unauthenticated attacker to change user account information, resulting in a denial of service (DoS) condition.
How severe is CVE-2019-16029?
CVE-2019-16029 has a severity rating of 9.1 (Critical).
Which software is affected by CVE-2019-16029?
Cisco Smart Software Manager On-Prem versions up to and including 7-201910 are affected by CVE-2019-16029.
How can an attacker exploit CVE-2019-16029?
An unauthenticated remote attacker can exploit CVE-2019-16029 by changing user account information, preventing users from logging in and causing a denial of service condition.
Is there a fix for CVE-2019-16029?
Yes, Cisco has released a security advisory with remediation steps for CVE-2019-16029. Please refer to the official Cisco Security Advisory for more information.