cisco dna-center CVE-2019-1841 vulnerability in Cisco Products
Published on April 18, 2019

Cisco DNA Center Unintended Proxy Via SWIM Import Interface Vulnerability
A vulnerability in the Software Image Management feature of Cisco DNA Center could allow an authenticated, remote attacker to access to internal services without additional authentication. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending arbitrary HTTP requests to internal services. An exploit could allow the attacker to bypass any firewall or other protections to access unauthorized internal services. DNAC versions prior to 1.2.5 are affected.

Vendor Advisory NVD

Weakness Type

What is a Confused Deputy Vulnerability?

The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.

CVE-2019-1841 has been classified to as a Confused Deputy vulnerability or weakness.


Products Associated with CVE-2019-1841

stack.watch emails you whenever new vulnerabilities are published in Cisco Dna Center or Cisco Catalyst Center. Just hit a watch button to start following.

 
 

Affected Versions

Cisco Digital Network Architecture Center (DNA Center):

Exploit Probability

EPSS
1.15%
Percentile
78.33%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.