CVE-2019-1857: Cisco HyperFlex HX-Series Web-Based Management Interface Cross-Site Request Forgery Vulnerability
A vulnerability in the web-based management interface of Cisco HyperFlex HX-Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected system by using a web browser and with the privileges of the user.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-1857?
CVE-2019-1857 is a vulnerability in the web-based management interface of Cisco HyperFlex HX-Series that could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system.
What is the severity of CVE-2019-1857?
The severity of CVE-2019-1857 is high, with a severity value of 8.8.
How can an attacker exploit CVE-2019-1857?
An attacker can exploit CVE-2019-1857 by conducting a cross-site request forgery (CSRF) attack through the web-based management interface of Cisco HyperFlex HX-Series.
What is the affected software of CVE-2019-1857?
The affected software of CVE-2019-1857 is Cisco HyperFlex HX-Series with specific firmware versions.
Are there any references for CVE-2019-1857?
Yes, you can find more information about CVE-2019-1857 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/108163) and [Cisco Security Advisory](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-hyperflex-csrf).