« Back to list

CVE-2019-19632

Status: ModifiedMedium (6.1)—

An issue was discovered in Big Switch Big Monitoring Fabric 6.2 through 6.2.4, 6.3 through 6.3.9, 7.0 through 7.0.3, and 7.1 through 7.1.3; Big Cloud Fabric 4.5 through 4.5.5, 4.7 through 4.7.7, 5.0 through 5.0.1, and 5.1 through 5.1.4; and Multi-Cloud Director through 1.1.0. An unauthenticated attacker may inject stored arbitrary JavaScript (XSS), and execute it in the content of authenticated administrators.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (3)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2019-19632",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-01-24T15:15:13.623",
  "references": [
    {
      "url": "https://know.bishopfox.com/advisories",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://know.bishopfox.com/advisories/big-monitoring-fabric",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://know.bishopfox.com/advisories",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://know.bishopfox.com/advisories/big-monitoring-fabric",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was discovered in Big Switch Big Monitoring Fabric 6.2 through 6.2.4, 6.3 through 6.3.9, 7.0 through 7.0.3, and 7.1 through 7.1.3; Big Cloud Fabric 4.5 through 4.5.5, 4.7 through 4.7.7, 5.0 through 5.0.1, and 5.1 through 5.1.4; and Multi-Cloud Director through 1.1.0. An unauthenticated attacker may inject stored arbitrary JavaScript (XSS), and execute it in the content of authenticated administrators."
    },
    {
      "lang": "es",
      "value": "Se detectó un problema en Big Switch Big Monitoring Fabric versiones 6.2 hasta 6.2.4, 6.3 hasta 6.3.9, 7.0 hasta 7.0.3 y 7.1 hasta 7.1.3; Big Cloud Fabric versiones 4.5 hasta 4.5.5, 4.7 hasta 4.7.7, 5.0 hasta 5.0.1 y 5.1 hasta 5.1.4; y Director Multi-Cloud versiones hasta 1.1.0. Un atacante no autenticado puede inyectar JavaScript (XSS) arbitrario almacenado y ejecutarlo en el contenido de administradores autenticados."
    }
  ],
  "lastModified": "2026-06-17T02:26:58.863",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:bigswitch:big_cloud_fabric:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "78DBA99A-E2AA-4B6C-9514-1B95C7C14E00",
              "versionEndExcluding": "4.5.5",
              "versionStartIncluding": "4.5"
            },
            {
              "criteria": "cpe:2.3:a:bigswitch:big_cloud_fabric:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D6B1226C-87F5-49FC-B872-3C73012C00A9",
              "versionEndExcluding": "4.7.7",
              "versionStartIncluding": "4.7"
            },
            {
              "criteria": "cpe:2.3:a:bigswitch:big_cloud_fabric:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C7CFCAA3-06CF-45C4-8640-2A3A7E397EEB",
              "versionEndExcluding": "5.0.1",
              "versionStartIncluding": "5.0"
            },
            {
              "criteria": "cpe:2.3:a:bigswitch:big_cloud_fabric:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "982B590C-D8E6-42FE-B3EA-525B50DD2FCA",
              "versionEndExcluding": "5.1.4",
              "versionStartIncluding": "5.1"
            },
            {
              "criteria": "cpe:2.3:a:bigswitch:big_monitoring_fabric:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "83BF3591-006A-4A0C-AB50-90F9E1C97E3D",
              "versionEndExcluding": "6.2.4",
              "versionStartIncluding": "6.2"
            },
            {
              "criteria": "cpe:2.3:a:bigswitch:big_monitoring_fabric:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F7711F6-3AA6-4D49-9AF1-E6AE87552EC7",
              "versionEndExcluding": "6.3.9",
              "versionStartIncluding": "6.3"
            },
            {
              "criteria": "cpe:2.3:a:bigswitch:big_monitoring_fabric:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "391CBB0B-A0A0-491C-8F88-96EB89BCAD83",
              "versionEndExcluding": "7.0.3",
              "versionStartIncluding": "7.0"
            },
            {
              "criteria": "cpe:2.3:a:bigswitch:big_monitoring_fabric:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1665CA5F-FDF1-409E-A36F-139EAF510D9A",
              "versionEndExcluding": "7.1.4",
              "versionStartIncluding": "7.1"
            },
            {
              "criteria": "cpe:2.3:a:bigswitch:multi-cloud_director:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B0037D82-D099-42A7-BB95-A4F91DA0166E",
              "versionEndExcluding": "1.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}