#VU17204 Information disclosure in Cisco AMP Threat Grid - CVE-2019-1657 

 

#VU17204 Information disclosure in Cisco AMP Threat Grid - CVE-2019-1657

Published: January 23, 2019 / Updated: January 24, 2019


Vulnerability identifier: #VU17204
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-1657
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Cisco AMP Threat Grid
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a remote authenticated attacker to obtain potentially sensitive information.

The vulnerability exists due to unsafe creation of API keys. A remote attacker can use insecure credentials to gain unauthorized access to information by using the API key credentials.


Remediation

The vulnerability has been addressed in the versions 2.5, 3.5.68.

External links