Lucene search

K
cveCiscoCVE-2019-1657
HistoryJan 24, 2019 - 4:29 p.m.

CVE-2019-1657

2019-01-2416:29:00
CWE-200
cisco
web.nvd.nist.gov
32
cisco
amp
threat grid
vulnerability
unauthorized access
nvd
cve-2019-1657

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4.7

Confidence

High

EPSS

0.001

Percentile

40.1%

A vulnerability in Cisco AMP Threat Grid could allow an authenticated, remote attacker to access sensitive information. The vulnerability is due to unsafe creation of API keys. An attacker could exploit this vulnerability by using insecure credentials to gain unauthorized access to the affected device. An exploit could allow the attacker to gain unauthorized access to information by using the API key credentials.

Affected configurations

Nvd
Node
ciscoamp_threat_grid_applianceRange<2.5
OR
ciscoamp_threat_grid_cloudRange<3.5.68
VendorProductVersionCPE
ciscoamp_threat_grid_appliance*cpe:2.3:a:cisco:amp_threat_grid_appliance:*:*:*:*:*:*:*:*
ciscoamp_threat_grid_cloud*cpe:2.3:a:cisco:amp_threat_grid_cloud:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Cisco AMP Threat Grid Appliance Software",
    "vendor": "Cisco",
    "versions": [
      {
        "status": "affected",
        "version": "n/a"
      }
    ]
  }
]

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4.7

Confidence

High

EPSS

0.001

Percentile

40.1%

Related for CVE-2019-1657