Skip to content
COOEY

EXPOSURES › CVE-2019-1895

CVE-2019-1895

CRITICAL
DETAIL
SourceNVD · cve Published2019-08-07 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-1895 ↗

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session of an administrative user on an affected device. The vulnerability is due to an insufficient authentication mechanism used to establish a VNC session. An attacker could exploit this vulnerability by intercepting an administrator VNC session request prior to login. A successful exploit could allow the attacker to watch the administrator console session or interact with it, allowing admin access to the affected device.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Vulnerability allows unauthenticated remote access to admin VNC console; insufficient auth mechanism; no praise for handling.
cooey ↗ severe-fallout -0.80
Severe: unauthenticated remote access to admin console via insufficient auth.
"A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session of an administrative user on an affected device."
The Register ↗ severe-fallout +0.00
Neutral: source text is navigation/menu, no coverage of CVE-2019-1895.
www.cvefind.com ↗ severe-fallout +0.00
Neutral: source text is navigation/menu, no coverage of CVE-2019-1895.
recentbreaches.com ↗ severe-fallout +0.00
Neutral: source text is navigation/menu, no coverage of CVE-2019-1895.
sec.cloudapps.cisco.com ↗ severe-fallout +0.00
Neutral: source text is navigation/menu, no coverage of CVE-2019-1895.
app.opencve.io ↗ severe-fallout +0.00
Neutral: source text is navigation/menu, no coverage of CVE-2019-1895.
AFFECTED FEDRAMP PRODUCTS · 7
PRODUCTSTATUS
Cisco Cloudlock for Government
Cisco Systems Inc.
Authorized
Cisco Meraki for Government
Cisco Systems Inc.
In Process
Cisco SD-WAN for Government
Cisco Systems Inc.
In Process
Cisco Umbrella for Government
Cisco Systems Inc.
In Process
Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government)
Cisco Systems Inc.
Authorized
WebEx Contact Center Enterprise for Government (WxCCE-G)
Cisco Systems Inc.
In Process
Webex for Government
Cisco Systems Inc.
Authorized