Security restrictions bypass in Cisco HyperFlex - CVE-2019-1667

 

Security restrictions bypass in Cisco HyperFlex - CVE-2019-1667

Published: February 22, 2019


Vulnerability identifier: #VU17835
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1667
CWE-ID: CWE-345
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local unauthenticated attacker to bypass security restrictions on the target system.

The vulnerability exists in the Graphite interface due to insufficient authorization controls. A local unauthenticated attacker can connect to the Graphite service and send arbitrary data to bypass security restrictions and write arbitrary data to Graphite, which could result in invalid statistics being presented in the interface.


Affected software

Cisco HyperFlex

How to mitigate CVE-2019-1667

Update to version 3.5(2a).

Cisco HyperFlex - update to 3.5.2a

External References

Related Security Bulletins