CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2019-1895

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1690%
EPSS Percentile5.09th
Published2019年8月7日
Last Modified2024年11月21日

Vulnerability Description

A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session of an administrative user on an affected device. The vulnerability is due to an insufficient authentication mechanism used to establish a VNC session. An attacker could exploit this vulnerability by intercepting an administrator VNC session request prior to login. A successful exploit could allow the attacker to watch the administrator console session or interact with it, allowing admin access to the affected device.

Affected Platforms (CPE)

📦
Cisco

Enterprise Network Function Virtualization Infrastructure

< 3.12.1

References & Advisories

相關漏洞威脅