Back
CVE-2019-1867
CRITICAL
A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication on the REST API. The vulnerability is due to improper validation of API requests. An attacker could exploit this vulnerability by sending a crafted request to the REST API. A successful exploit could allow the attacker to execute arbitrary actions through the REST API with administrative privileges on an affected system.
Published: May 10, 2019
Modified: Jun 17, 2026
CWE-287
CWE-287
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| cisco | elastic_services_controller | * ≥ 4.1 < 4.5 |
GitHub Security Advisory GHSA-gfx3-865x-23hf
A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an...
Risk Scores
CVSS Score
10.0 / 10
EPSS Score
30.34%
Top 2% most likely to be exploited
Threat Score
49.1 / 100
Data Sources
NVD
EPSS
GitHub