CVE-2019-1903: Cisco Security Manager XML Entity Expansion Vulnerability
A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of service (DoS) condition. The vulnerability is due to improper restrictions on XML entities. An attacker could exploit this vulnerability by sending malicious requests to a targeted system that contain references within XML entities. An exploit could allow the attacker to retrieve files from the local system, resulting in the disclosure of sensitive information, or cause the application to consume available resources, resulting in a DoS condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1903?
The severity of CVE-2019-1903 is high due to its potential to allow unauthorized access to sensitive information and cause denial of service.
How do I fix CVE-2019-1903?
To fix CVE-2019-1903, upgrade to the latest version of Cisco Security Manager that addresses this vulnerability.
Who is affected by CVE-2019-1903?
CVE-2019-1903 affects users of Cisco Security Manager version 4.14-sp2.
What type of attacks can be executed through CVE-2019-1903?
An attacker can execute remote code execution or denial of service attacks through CVE-2019-1903 due to improper restrictions on XML entities.
Is authentication required to exploit CVE-2019-1903?
No, authentication is not required to exploit CVE-2019-1903, allowing unauthenticated attackers to exploit it.