Back

CVE-2019-1867

CRITICAL

A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication on the REST API. The vulnerability is due to improper validation of API requests. An attacker could exploit this vulnerability by sending a crafted request to the REST API. A successful exploit could allow the attacker to execute arbitrary actions through the REST API with administrative privileges on an affected system.

Published: May 10, 2019 Modified: Jun 17, 2026
CWE-287 CWE-287

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: CHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
cisco elastic_services_controller * ≥ 4.1 < 4.5

GitHub Security Advisory GHSA-gfx3-865x-23hf

A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 30.34%

Top 2% most likely to be exploited

Threat Score 49.1 / 100

Data Sources

NVD EPSS GitHub