SB2019071718 - Improper Authentication in Cisco Vision Dynamic Signage Director



SB2019071718 - Improper Authentication in Cisco Vision Dynamic Signage Director

Published: July 17, 2019 Updated: July 18, 2019

Security Bulletin ID SB2019071718
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Authentication (CVE-ID: CVE-2019-1917)

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to insufficient validation of HTTP requests in the REST API interface. A remote attacker can send a crafted HTTP request to an affected system, bypass authentication process, gain unauthorized access to the application and  execute arbitrary actions through the REST API with administrative privileges on the affected system.


Remediation

Install update from vendor's website.