SB2019071718 - Improper Authentication in Cisco Vision Dynamic Signage Director
Published: July 17, 2019 Updated: July 18, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Authentication (CVE-ID: CVE-2019-1917)
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to insufficient validation of HTTP requests in the REST API interface. A remote attacker can send a crafted HTTP request to an affected system, bypass authentication process, gain unauthorized access to the application and execute arbitrary actions through the REST API with administrative privileges on the affected system.
Remediation
Install update from vendor's website.