ID

VAR-201905-0604


CVE

CVE-2019-1852


TITLE

Cisco Prime Network Registrar Vulnerable to cross-site scripting

Trust: 0.8

sources: JVNDB: JVNDB-2019-003898

DESCRIPTION

A vulnerability in the web-based management interface of Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks. This issue is being tracked by Cisco Bug ID CSCvo74414. The product provides services such as Dynamic Host Configuration Protocol (DHCP), Domain Name System (DNS) and IP Address Management (IPAM)

Trust: 1.98

sources: NVD: CVE-2019-1852 // JVNDB: JVNDB-2019-003898 // BID: 108145 // VULHUB: VHN-150874

AFFECTED PRODUCTS

vendor:ciscomodel:network registrarscope:eqversion:9.1\(2\)

Trust: 1.0

vendor:ciscomodel:prime network registrarscope: - version: -

Trust: 0.8

vendor:ciscomodel:prime network registrarscope:eqversion:0

Trust: 0.3

vendor:ciscomodel:network registrarscope:eqversion:9.1(2)

Trust: 0.3

sources: BID: 108145 // JVNDB: JVNDB-2019-003898 // NVD: CVE-2019-1852

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-1852
value: MEDIUM

Trust: 1.0

ykramarz@cisco.com: CVE-2019-1852
value: MEDIUM

Trust: 1.0

NVD: CVE-2019-1852
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201905-051
value: MEDIUM

Trust: 0.6

VULHUB: VHN-150874
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2019-1852
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-150874
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-1852
baseSeverity: MEDIUM
baseScore: 6.1
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 2.7
version: 3.0

Trust: 2.8

sources: VULHUB: VHN-150874 // JVNDB: JVNDB-2019-003898 // CNNVD: CNNVD-201905-051 // NVD: CVE-2019-1852 // NVD: CVE-2019-1852

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-150874 // JVNDB: JVNDB-2019-003898 // NVD: CVE-2019-1852

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201905-051

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201905-051

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-003898

PATCH

title:cisco-sa-20190501-pnr-xssurl:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-pnr-xss

Trust: 0.8

title:Cisco Prime Network Registrar Fixes for cross-site scripting vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=92194

Trust: 0.6

sources: JVNDB: JVNDB-2019-003898 // CNNVD: CNNVD-201905-051

EXTERNAL IDS

db:NVDid:CVE-2019-1852

Trust: 2.8

db:BIDid:108145

Trust: 1.0

db:JVNDBid:JVNDB-2019-003898

Trust: 0.8

db:CNNVDid:CNNVD-201905-051

Trust: 0.7

db:AUSCERTid:ESB-2019.1534

Trust: 0.6

db:VULHUBid:VHN-150874

Trust: 0.1

sources: VULHUB: VHN-150874 // BID: 108145 // JVNDB: JVNDB-2019-003898 // CNNVD: CNNVD-201905-051 // NVD: CVE-2019-1852

REFERENCES

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20190501-pnr-xss

Trust: 2.0

url:https://nvd.nist.gov/vuln/detail/cve-2019-1852

Trust: 1.4

url:http://www.cisco.com/

Trust: 0.9

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-1852

Trust: 0.8

url:https://www.auscert.org.au/bulletins/80174

Trust: 0.6

url:https://www.securityfocus.com/bid/108145

Trust: 0.6

sources: VULHUB: VHN-150874 // BID: 108145 // JVNDB: JVNDB-2019-003898 // CNNVD: CNNVD-201905-051 // NVD: CVE-2019-1852

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 108145

SOURCES

db:VULHUBid:VHN-150874
db:BIDid:108145
db:JVNDBid:JVNDB-2019-003898
db:CNNVDid:CNNVD-201905-051
db:NVDid:CVE-2019-1852

LAST UPDATE DATE

2024-11-23T21:52:17.237000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-150874date:2019-10-09T00:00:00
db:BIDid:108145date:2019-05-01T00:00:00
db:JVNDBid:JVNDB-2019-003898date:2019-05-23T00:00:00
db:CNNVDid:CNNVD-201905-051date:2019-05-07T00:00:00
db:NVDid:CVE-2019-1852date:2024-11-21T04:37:31.930

SOURCES RELEASE DATE

db:VULHUBid:VHN-150874date:2019-05-03T00:00:00
db:BIDid:108145date:2019-05-01T00:00:00
db:JVNDBid:JVNDB-2019-003898date:2019-05-23T00:00:00
db:CNNVDid:CNNVD-201905-051date:2019-05-01T00:00:00
db:NVDid:CVE-2019-1852date:2019-05-03T17:29:01.250