First published: Thu Jan 24 2019(Updated: )
A vulnerability in the Cisco Connected Mobile Experiences (CMX) software could allow an unauthenticated, adjacent attacker to access sensitive data on an affected device. The vulnerability is due to a lack of input and validation checking mechanisms for certain GET requests to API's on an affected device. An attacker could exploit this vulnerability by sending HTTP GET requests to an affected device. An exploit could allow the attacker to use this information to conduct additional reconnaissance attacks.
Credit: ykramarz@cisco.com ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Connected Mobile Experiences | =10.2\(1.0\) | |
=10.2\(1.0\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1645 is a vulnerability in the Cisco Connected Mobile Experiences (CMX) software that could allow an unauthenticated, adjacent attacker to access sensitive data on an affected device.
CVE-2019-1645 is due to a lack of input and validation checking mechanisms for certain GET requests to API's on an affected device, allowing the attacker to access sensitive data.
The severity of CVE-2019-1645 is medium with a CVSS score of 4.3.
To check if you are affected by CVE-2019-1645, verify that you have Cisco Connected Mobile Experiences (CMX) software version 10.2(1.0) installed on your device.
To fix CVE-2019-1645, Cisco has released a security advisory that provides information on the necessary updates and patches. Please refer to the Cisco Security Advisory for guidance.