Summary
Detail | |||
---|---|---|---|
Vendor | Cisco | First view | 2019-05-03 |
Product | Ucs c480 Ml Firmware | Last view | 2019-05-03 |
Version | Type | Os | |
Update | |||
Edition | |||
Language | |||
Sofware Edition | |||
Target Software | |||
Target Hardware | |||
Other |
Activity : Overall
COMMON PLATFORM ENUMERATION: Repartition per Version
CPE Name | Affected CVE |
---|---|
cpe:2.3:o:cisco:ucs_c480_ml_firmware:3.0(1a):*:*:*:*:*:*:* | 1 |
Related : CVE
Date | Alert | Description | |
---|---|---|---|
8.8 | 2019-05-03 | CVE-2019-1857 | A vulnerability in the web-based management interface of Cisco HyperFlex HX-Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is due to insufficient CSRF protections for the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on an affected system by using a web browser and with the privileges of the user. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
100% (1) | CWE-352 | Cross-Site Request Forgery (CSRF) |