« Volver al listado

CVE-2019-1975

Estado: ModificadaMedia (6.1)—

A vulnerability in the web-based interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to execute a cross-frame scripting (XFS) attack on an affected device. This vulnerability is due to insufficient HTML iframe protection. An attacker could exploit this vulnerability by directing a user to an attacker-controlled web page that contains a malicious HTML iframe. A successful exploit could allow the attacker to conduct clickjacking or other clientside browser attacks.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-1975",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2019-1975",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-11-21T18:57:02.844782Z"
        }
      }
    ],
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "psirt@cisco.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@cisco.com",
      "affectedData": [
        {
          "vendor": "Cisco",
          "product": "Cisco HyperFlex HX-Series",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "3.5.2f",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-09-18T17:15:16.240",
  "references": [
    {
      "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190918-hyperflex-xfs",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@cisco.com"
    },
    {
      "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190918-hyperflex-xfs",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@cisco.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-693"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1021"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability in the web-based interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to execute a cross-frame scripting (XFS) attack on an affected device. This vulnerability is due to insufficient HTML iframe protection. An attacker could exploit this vulnerability by directing a user to an attacker-controlled web page that contains a malicious HTML iframe. A successful exploit could allow the attacker to conduct clickjacking or other clientside browser attacks."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad en la interfaz basada en web de Cisco HyperFlex Software podría permitir a un atacante remoto no autenticado ejecutar un ataque de tipo cross-frame scripting (XFS) sobre un dispositivo afectado. Esta vulnerabilidad es debido a una protección insuficiente de iframe HTML. Un atacante podría explotar esta vulnerabilidad mediante el direccionamiento de un usuario a una página web controlada por el atacante que contenga un iframe HTML malicioso. Una explotación con éxito podría permitir al atacante conducir ataques de secuestro de cliqueo u otros ataques del navegador del lado del cliente."
    }
  ],
  "lastModified": "2026-06-17T02:29:43.917",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:cisco:hyperflex_hx220c_m5_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "26D4C3A6-0F94-4CF0-ACE4-2EDAE89683D4",
              "versionEndIncluding": "3.5.2f"
            },
            {
              "criteria": "cpe:2.3:o:cisco:hyperflex_hx220c_m5_firmware:4.0\\(1a\\):*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7BD4667C-6C1C-4A02-A84F-D743CF5FD2D4"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:cisco:hyperflex_hx220c_m5:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "6E19D6AF-E190-463D-B359-BB02362490D1"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:cisco:hyperflex_hx240c_m5_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "82D79767-9755-4205-A5B5-11E2D4EBAF96",
              "versionEndIncluding": "3.5.2f"
            },
            {
              "criteria": "cpe:2.3:o:cisco:hyperflex_hx240c_m5_firmware:4.0\\(1a\\):*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D976395-899C-4118-ABAD-623466865677"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:cisco:hyperflex_hx240c_m5:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5009EC3A-40C9-44B0-8E5E-599657F819FA"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:cisco:hyperflex_hx220c_af_m5_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "09D5D06D-B784-443E-A3FD-CB232D3FCEBC",
              "versionEndIncluding": "3.5.2f"
            },
            {
              "criteria": "cpe:2.3:o:cisco:hyperflex_hx220c_af_m5_firmware:4.0\\(1a\\):*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CBDE16F7-0676-40AE-AC18-ECE0052AB2C4"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:cisco:hyperflex_hx220c_af_m5:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0D5AFDE1-3A3B-4AF8-A425-492558B0B2EA"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:cisco:hyperflex_hx240c_af_m5_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D8BE40D9-6230-4CE3-A1B3-DE97052C7BCE",
              "versionEndIncluding": "3.5.2f"
            },
            {
              "criteria": "cpe:2.3:o:cisco:hyperflex_hx240c_af_m5_firmware:4.0\\(1a\\):*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A67370EF-223A-46B5-BB5D-67D48CD6016F"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:cisco:hyperflex_hx240c_af_m5:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "EFF775A8-5A2C-42B7-B26C-85921D803A25"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:cisco:hyperflex_hx220c_edge_m5_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "00CE0E89-E6F9-4147-A0AD-56CCA87D1307",
              "versionEndIncluding": "3.5.2f"
            },
            {
              "criteria": "cpe:2.3:o:cisco:hyperflex_hx220c_edge_m5_firmware:4.0\\(1a\\):*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D1E08B56-04D5-45EF-8226-104164221326"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:cisco:hyperflex_hx220c_edge_m5:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9B38E0BA-D320-406B-8739-6218B96DFD24"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "psirt@cisco.com"
}