MEDIUM · 6.5

CVE-2019-1690

A vulnerability in the management interface of Cisco Application Policy Infrastructure Controller (APIC) software could allow an unauthenticated, adjacent attacker to gain unauthorized access on an af...

Vulnerability Description

A vulnerability in the management interface of Cisco Application Policy Infrastructure Controller (APIC) software could allow an unauthenticated, adjacent attacker to gain unauthorized access on an affected device. The vulnerability is due to a lack of proper access control mechanisms for IPv6 link-local connectivity imposed on the management interface of an affected device. An attacker on the same physical network could exploit this vulnerability by attempting to connect to the IPv6 link-local address on the affected device. A successful exploit could allow the attacker to bypass default access control restrictions on an affected device. Cisco Application Policy Infrastructure Controller (APIC) devices running versions prior to 4.2(0.21c) are affected.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
CiscoApplication Policy Infrastructure Controller< 4.2\(0.21c\)
CiscoFirepower 2110-
CiscoFirepower 2120-
CiscoFirepower 2130-
CiscoFirepower 2140-
CiscoFirepower 4110-
CiscoFirepower 4112-
CiscoFirepower 4115-
CiscoFirepower 4120-
CiscoFirepower 4125-
CiscoFirepower 4140-
CiscoFirepower 4145-
CiscoFirepower 4150-
CiscoFirepower 9300-
CiscoMds 9100-
CiscoMds 9134-
CiscoMds 9509-
CiscoMds 9710-
CiscoNexus 3016-
CiscoNexus 3048-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-1690?

CVE-2019-1690 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A vulnerability in the management interface of Cisco Application Policy Infrastructure Controller (APIC) software could allow an unauthenticated, adjacent attacker to gain unauthorized access on an af...

How severe is CVE-2019-1690?

CVE-2019-1690 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-1690?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Application Policy Infrastructure Controller, Cisco Firepower 2110, Cisco Firepower 2120, Cisco Firepower 2130, Cisco Firepower 2140.