CVE-2019-1666

MEDIUM

Cisco HyperFlex HX Data Platform < 3.5(2a) - Unauthenticated Data Retrieval via Graphite Service

Title source: llm
STIX 2.1

Description

A vulnerability in the Graphite service of Cisco HyperFlex software could allow an unauthenticated, remote attacker to retrieve data from the Graphite service. The vulnerability is due to insufficient authentication controls. An attacker could exploit this vulnerability by sending crafted requests to the Graphite service. A successful exploit could allow the attacker to retrieve any statistics from the Graphite service. Versions prior to 3.5(2a) are affected.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/107108

Scores

CVSS v3 5.3
EPSS 0.0221
EPSS Percentile 80.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-284 CWE-287
Status published
Products (12)
cisco/hyperflex_hx_data_platform 2.6\(1a\)
cisco/hyperflex_hx_data_platform 2.6\(1b\)
cisco/hyperflex_hx_data_platform 2.6\(1d\)
cisco/hyperflex_hx_data_platform 2.6\(1e\)
cisco/hyperflex_hx_data_platform 3.0\(1a\)
cisco/hyperflex_hx_data_platform 3.0\(1b\)
cisco/hyperflex_hx_data_platform 3.0\(1c\)
cisco/hyperflex_hx_data_platform 3.0\(1d\)
cisco/hyperflex_hx_data_platform 3.0\(1e\)
cisco/hyperflex_hx_data_platform 3.0\(1h\)
... and 2 more
Published Feb 21, 2019
Tracked Since Feb 18, 2026